...especially considering the fact that a lot of IDS's out there are looking at protocol violations as an attack on the network. Just because the "virus" would be doing something "good", the program would still be violating a protocol's RFC and therefor would be blocked.
