Best to ask this via Private message but as that is not reliable at present I will accept the question here though best to keep the discussion short to not divert from the Op's issue.
This was not malware, just to be clear, this is as false detection thread. That said, ATD can leverage the cloud, and if a sample has a "dirty" classification, then ATD will flag it. Bear in mind, that's not all ATD does, it also does sandboxing, and applies a score to the various activities of the file. In this case, ATD does not flag any of the behavior as malicious/suspicious. Level = 0. (Typically you would need to ask the ATD team for such info)