I started receiving suspicious file alerts from my server's firewall as follows:
Time: Mon Jul 23 13:10:39 2012 -0400
File: /tmp/RokCommon51542e7480feefda3a74605e6cde3fadServiceContainer.php
Reason: Script, file extension
Owner: *****:****** (******:*******)
Action: Moved into /etc/csf/suspicious.tar
The alerts came every two minutes. In researching the possible cause I found
this post
and proceeded to delete RokCommon as instructed by Ben with the intention of reinstalling RokGallery to recover RokCommon.
Well, RokCommon uninstalled fine, but it crashed my site. I uninstalled RokGallery, but now I cannot get it to reinstall. And, the site is down. I can access the Joomla CP, but that's it.
Ok, I plowed through it and got it resolved. I was able to manually delete files through FTP until I was able to reinstall RokGallery, which brought the site back up. That was scary! :shock: