This was a real helpful post, unfortunately I fell victim to a wallet stealer as well for $400 USD
....well not technically a wallet stealer but I had went to some TOR website and apparently someone was able to do a JAVA-ish type drive-by on me and I was on MtGox at the time and they were able to steal my wallet just based on my cookie info. I guess sometimes the best lessons have to be learned the hard way.

Did you use something other than the packaged TOR browser? Java should be disabled.
That's why I said Java-ish, I'm not really sure at all. All I know for sure is after visiting the site I felt something was wrong with my computer, but unfortunately didn't act on it and next thing you know my rent money I had made was drained from my MtGox account.