Windows ShadowCopy file flagged as EmailWorm.Win32.Joleee.~J5@112461068

My backup application which uses the Microsoft Volume Shadow Copy Service (VSS) has been failing due to ‘Access denied’ to a single file in the shadow copy location being detected falsely as EmailWorm.Win32.Joleee.~J5@112461068 and put in Quarantine.
The original file located in C:\Windows\System32\en-US\slcext.dll.mui does not trigger this same virus alert and quarantine action.
Because the file is detected in the shadow copy location it cannot be excluded from antivirus scans as the location cannot be selected plus is constantly changing.

Date & Time Location Malware Name Action Status
2018-07-27 17:07:31 \Device\HarddiskVolumeShadowCopy4\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success
2018-07-27 16:33:07 \Device\HarddiskVolumeShadowCopy1\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success
2018-07-17 16:53:17 \Device\HarddiskVolumeShadowCopy3\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success
2018-07-15 21:40:13 \Device\HarddiskVolumeShadowCopy9\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success
2018-07-15 19:58:18 \Device\HarddiskVolumeShadowCopy3\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success
2018-07-15 13:21:40 \Device\HarddiskVolumeShadowCopy2\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success
2018-07-15 09:39:47 \Device\HarddiskVolumeShadowCopy13\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success
2018-07-15 00:43:49 \Device\HarddiskVolumeShadowCopy2\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success
2018-07-14 09:12:04 \Device\HarddiskVolumeShadowCopy7\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success
2018-07-13 23:07:16 \Device\HarddiskVolumeShadowCopy3\Windows\System32\en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5@112461068 Quarantine Success

Hi droyls,

Could you please submit the detected file <en-US\slcext.dll.mui EmailWorm.Win32.Joleee.~J5[at]112461068> at

This is to inform you pdf that false-positive has been fixed.
You can update to AV database Version < 29424 > of Comodo Internet Security Version<10.2.0.6526> and confirm it.
<uninst.exe #qigdpzydmgn3 Sha1:5d8b6268eeec9d8d904bc9d988a4b588b392213f>
<Run.exe #1nkmu9rfmstjj Sha1:2759756d13c9aaa90bb044fde365fb2be38285d5>

Best regards
Qiuhui.■■■■

Thank you for the quick reply. I have updated to to AV database Version < 29424 > of Comodo Internet Security Version<10.2.0.6526> and also submitted the detected file <en-US\slcext.dll.mui as requested.
It will take a little while to confirm that the false positive has been resolved when running my backup application due to the size of data involved (approximately 80GB being backed up to a cloud server).