For only some malware like the one below, the file antivirus is asking for user decision but for other malware, it automatically blocked the startup and then deleted it.
Event: Malicious object detected
User: xxx\xxxx
User type: Active user
Application name: WinRAR.exe
Application path: C:\Program Files\WinRAR
Component: File Anti-Virus
Result description: Detected
Type: Trojan
Name: HEUR:Trojan-PSW.MSIL.Agensla.gen
Precision: Heuristic Analysis
Threat level: High
Object type: File
Object name: 57520e51bb0820741b7883926800223886c491a8a5ddd517a49b0e2cc752fb18.exe
Object path: C:\Users\xxxx\AppData\Local\Temp\Rar$EXb11728.44259
MD5: BAED30AEA51E6000571219633AA745B0
Reason: Machine learning
Databases release date: Today, 02-12-2022 13:14:00