Hi Pondus,

Even ComboFix is marked as malware in VirusTotal scan. See here.

This is one of reasons why helpers asks the victims to temporary disable the anti-virus shield before proceeding with the shield.
One of the reasons can be the following –

During the process of removing malware from your computer, there are times you may need to use specialized fix tools. This is especially true if you are receiving help from a member of the HJT Team. Certain embedded files that are part of these specialized fix tools may at times be detected by your anti-virus or anti-malware scanner as a "RiskTool", "Hacking tool", "Potentially unwanted tool", a virus or a "Trojan" when that is not the case.

These tools have been carefully created and tested by security experts so if your anti-virus or anti-malware program flags them as malware, the detection is what’s known as a “False Positive”. Anti-virus scanners cannot distinguish between “good” and “malicious” use of such programs, therefore they may alert you or even automatically remove them. In these cases, the removal of these files can have “unpredictable results” and unintentional results.

Source: http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/