Many thanks Sigbjorn. What white list are you referring to, I can't see anywhere within Threat Extraction to add MD5 check sum?
I can only see two places where files can be excluded.
1. Inspect all domains and files except Trusted Sites
2. Prevent legitimate applications exploitation attempts
"1. Inspect all domains and files except Trusted Sites" I can see the domain could be added so that could be an option for trusted sites, there is also an option to add SHA1 HASH. Would adding a file here exclude Web Download Emulation ?
"2. Prevent legitimate applications exploitation attempts" I can see a process can be added but only as process path. Would adding file as *\Support-LogMeInRescue.exe exclude Web Download Emulation ?