> Source: [sk115892](https://support.checkpoint.com/results/sk/sk115892)

# sk115892 - "An error has occurred while extracting file" log from Threat Extraction blade when it blocks files attached to e-mails

| Property | Value |
|----------|-------|
| Solution ID | sk115892 |
| Date Created | 2017-02-12 |
| Last Modified | 2019-10-02 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Files attached to e-mails are blocked by the Threat Extraction blade with the following log in SmartView Tracker / SmartLog:

  `
  Product: Threat Extraction`  
  `
  Threat Extraction Activity: An error has occurred while extracting file`  
  `
  Protection Name: Potential malicious content extracted`  
  `
  Protection Type: Content Removal`  
  `
  File Name: <Name_of_Attached_File>`  
  `
  Service: smtp (25)`  
  `
  `
* Debug of *in.emaild.mta* daemon (per [sk60387](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk60387)) on Security Gateway shows:

  `
  [emaild.mta PID ...]@GW_HostName[Date Time] email_policy_scrub_replace_part : failed to replace mime part rc=-1 mime_file_name=/opt/CPsuite-R77/fw1/tmp/email_tmp/emailtemp-... attachment_name=<Name_of_Attached_File> scrubbed_disk_file=/tmp/scrub/{...}/<Name_of_Attached_File>`  
  `
  [emaild.mta PID ...]@GW_HostName[Date Time] email_policy_scrub_handle_scrub_result: email_policy_scrub_replace_part failed`  
  `
  [emaild.mta PID ...]@GW_HostName[Date Time] mime_get_file_type_action: avift_new_file failed`  
  `
  [emaild.mta PID ...]@GW_HostName[Date Time] email_policy_scrub_strip_attachment: mime_part_replace failed. rc=-1`  
  `
  ... ...`  
  `
  [emaild.mta PID ...]@GW_HostName[Date Time] [SCRUB (TD::All)] scrub_log_build_activity_str: Extracting activity: 'An error has occurred while extracting file'
  `

## Cause

This issue occurs when there are files in e-mail attachment with the same file name and file extension, but they differ only by the case of their detected file extension (e.g., "file.PDF" vs. "file.pdf", "file.DOCX" vs. "file.docx").

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
