In fact most of them don't even understand how it works, if they did, they can't logically accept such mechanism especially in our time.
If webroot would virtualize the whole system then it will works, but not the way it is implemented now. The rollback machanism can't cope with 50+Gb of modified datas.
I always figured the most efficient way to do that was capture the encryption key in memory, not that your AV should be grabbing those.