This is something that I have seen in AVG in the past where it’s too late to detect the threat.I am not sure if this is intended behaviour though…