Andrey, the problem would be then the false negative.
The user with an infected computer will think it is a false positive, return back to the old virus definitions, and the infection will do more harm then if it is get blocked by the new definitions.
I think false positives (specially system ones) should be addressed by the streaming updates. I could not understand why it took so long to correct the recent tcpip.sys false positive on XP machines... Poor user experience.