The win32:Agent is a bit of a strange bird really as it has a great number of variants, usually a trojan downloader though. What is strange about it is that it has been detected by signature rather than by a generic (family style) signature or heuristics by those that did detect it.

I still think there is a likelihood it is a false detection so you were correct in sending a sample for analysis. I trust you gave as much info as possible and putting False Positive in the subject and body of the email, hopefully that will be filtered and dealt with quickly.