It's often useful to take a sample of a suspected false positive and upload it to http://virustotal.com/ to get the opinion of 20 or so other virus scanners as well as a community reputation score.
One person's "need this to do support" is another organization's "unauthorized remote control software" so it's possible that once you have verified that the software you've gotten is legitimate and clean that you'd want to add that to your exception list in ePO's VSE policy.
If it's being flagged as entirely malicious and not just potentially unwanted software, and it's a false positive, you can submit a sample to mcafee as a suspected false positive via https://www.webimmune.net/
W32/Ramnit.a.dr is a noted false positive, and it will be resolved in the next dat release (6191 - should be out in about 5 hours from now)
Thanks for getting this fixed, if you need anything from Citrix please let me know.
Glenn Dobson | Community Leader, Social Media
Citrix Online Division http://www.citrixonline.com/ Citrix Systems, Inc.
On Twitter @GlennDCitrix
I've tested the file against dat 6191 and the false positive has been removed. So after updating to the latest dat it should be resolved.
Thank you all for your responses. This has been resolved.