> Source: [sk115107](https://support.checkpoint.com/results/sk/sk115107)

# sk115107 - "An error has occurred while extracting file" message in Threat Extraction log when processing an attached image file

| Property | Value |
|----------|-------|
| Solution ID | sk115107 |
| Date Created | 2016-12-20 |
| Last Modified | 2017-05-17 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- Log from Threat Extraction blade shows:  
The File 'xxx' sent from Alias1@Domain1 to Alias2@Domain2 was bypassed by the Threat Extraction policy

|----------------------------|---------------------------------------------|
| Threat Extraction Activity | An error has occurred while extracting file |
| Protection Name            | Potential malicious content extracted       |
| Protection Type            | Content Removal                             |

*Example (Threat Extraction Profile is set to "Allow" corrupted files)*:
[![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115107/Log.jpg)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115107/Log.jpg "Click the image to see it in full size in a new tab/window")

## Cause

Threat Extraction might print incorrect log message if the image file that was attached to an e-mail was corrupted.

**Note:** Whether to "Allow" or "Block" corrupted files in the attachment is controlled by the Threat Prevention Profile assigned to the Security Gateway (in SmartDashboard, go to "Threat Prevention" tab - in the left upper pane, click on "Profiles" - edit the relevant profile - expand the "Threat Extraction" pane - click on "Advanced" - refer to the "Threat Extraction Exceptions" section).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
