If I remember correctly the recommended action of the ant-rootkit module is dependent on the surety of the detection.

If it’s an uncertain heuristic detection, the user prompt is “ignore (recommended)”.

If it’s a definite match, it comes up “delete (recommended)”. Now in this case an FP would be deleted and this could be a headache for the user.

Of course it would be great to have a “move to chest” option but I can only conclude that it’s not there because it’s not viable. My guess is that it has something to do with the nature of rootkits and operational limitations within Windows itself. Let’s say avast! detects a hidden rootkit driver. It’s hard enough in the first place to remove/kill it without a causing a freeze or BSOD. it’s another thing again to be able to kill it and simultaneously take a copy of an invisible process to put in the virus chest.