So you would whitelist an infected copy of Adobe ? A whitelist is based on file name not behaviour. Sandbox works on behaviour not name