ComboFix Anti-malware software compromised
BleepingComputer.com has reported that the ComboFix distribution that was being hosted on their site was found to contain a file infected with the Sality virus. The compromised version was found yesterday and traced to the download package updated at 2am on Jan 29th. Other sites have mirrored the infected files so if you have downloaded and used ComboFix within the past 24hours then your system may be infected with Sality. If you already had your copy of ComboFix prior to yesterdays update then your files are clean and you can continue to use it without worrying.
Most Anti-Virus program programs will catch Sality because it is fairly old. But keep in mind not all users keep antivirus programs up to date and if you are needing to run ComboFix then chances are that the system is already compromised by some virus and the anti-virus program may already be disabled.
If these sites are being blocked then you are most likely already infected, use a clean computer and download the SalityKiller from Kasperski or the AVG Sality removal tool after disconneecting your system from your network on internet connection.
The Sality virus can be spread via network shares and infected files. If you are on a network you will need to scan the other systems that are connected in case the virus has already spread thru the network shares.
Additional details are available at the BleepingComputer.com web site.