Auto-Protect/SONAR with Rootkits

I posted about having ZeroAccess Rootkit.

 

If SONAR is active, why does it not detect the Rookit? It would be doing something destructive and not doing anything...

It takes a scan in Safe mode to get rid of it, but Auto-Protect and SONAR don't detect it?!

What if I would have had Safeboot off or whatever, it could have BSOD'd me!

If Symantec make it where they're just detected by Auto-Protect and SONAR that would be good.

 

By the way, why do I have to restart when Backdoor.Graybird is detected?

And I downloaded Trojan.Vundo.B Auto-Protect 'Processed' it and said I

had to restart?