sdra64.exe and Norton AV 2009

I have Norton AV 2009 and after seeing my Windows firewall turned off, I noticed entries in the Norton log mentioning changes to files and registry entries by sdr64.exe...

 

Why did Norton not prevent the infection by sdra64.exe in the first place, and why did it allow changes to Winlogon etc?

 

I eventually used Malwarebytes to remove the infection.

 

It certainly seems to be an unsatisfactory performance on the part of Norton AV 2009.