The AV/FW solutions these days have options for advanced users to display a message on every suspicious event. So in general any packer or executable can lead to false positive with such feature enabled. Guess it is the end-user who doesn't have the ability to interpreted the difference between a real virus and a warning.

To explain why you might get a virus warning on nacasi packed executables (a real false positive). Simple, some wana-hackers/virus writers use software like nacasi to distribute their payloads.


smile