According to Microsoft's own blog post (http://blogs.technet.com/b/mmpc/archive/2014/01/09/tackling-...), they specifically removed a non-self-updating version of Tor, which was installed by the Sefnit malware. This version of Tor contained a number of security vulnerabilities which would otherwise be left on the victim's computer. They also consulted Tor developers to plan the cleanup.
Other legitimate software often removed or marked as malware: