Ok you do your job trusting antivirus programs after the machine has been infected and I wish you luck. That's all.
You know the infection already got past your active antivirus when you get in the OP position in the first place!
First it fails to protect you and then it SAVES THE DAY!
What an earth are you talking about?
You're not making much sense you know.
Let me explain...
1. 0 Day exploit is released.
2. User receives email with 0 day exploit based malware attached
3. AV misses it on a signature scan due to no signature existing yet
4. User tries to run attachment
5. AV blocks malware based on behavior at execution (could be any number of triggers)
It's not that hard to comprehend is it?