Any by the Way - there is no longer any Option to send Files to Symantec to let them see and check that the Files are beeing detected by SONAR without any Reason.
I have my doubts this will be resolved soon and effectively, especially for people that use executables/tools that are not used widespread -- which seems the be the criteria used by SONAR. I.e., this is not like Auto-Protect which I assume uses known signatures, etc.
Once you restore the files SONAR wont touch them. So something else is going on here. Can you look through the Security History logs for anything suspicious. Specifically look in the Tamper Protection area.