I've looked at the source, and I think it's great that it's detected as malware by av products and PFW products. Wasn't VB touting how his POC code will bypass all PFW solutions? Didn't I already say it didn't work on the machines I've tested it on? Why would you want something that proves PFW's don't work to NOT be detected as malware?
It seems to me that if the PFW/AV solutions are doing their job, that the POC would be detected and blocked. While that may not have been VB's intent, it shows that PFW/AV vendors are learning about new/different vectors and properly detecting them.