It’s simple: There is a virus which could have several different layers on itself (have you seen Shrek ;D ?). With these layers, it could not be executed directly but must be unpacked first. And it does not matter if it is ZIP, MiME etc. Unless it is unpacked, it is just “data” - it acutally cannot spread in this form.

Of course, the EXE packers are different - with Pklite or UPX, it is decrypted on the fly in the moment of execution - and it could carry its envelope with itself…

Sometimes it is good to detect even the packed “data” form (especially for the mail servers - like the encrypted Beagle variants) but such files can’t be executed directly and after unpacking the virus could be detected in its native form.

Hope this helps
Pavel