It is possible for your child to tamper with the system and to get notified later, such as after a reboot.
Is that the case here, the machine was restarted?
Do you see the paw icon in the tray?
Matt
It is possible for your child to tamper with the system and to get notified later, such as after a reboot.
Is that the case here, the machine was restarted?
Do you see the paw icon in the tray?
Matt
Nope, he knows if he did he'd NEVER be allowed on the computer again. Case closed, no questions asked. He has no idea what our passwords are, I rotate 4 of them all the time. He has no desire to even try and figure out how to log into "my side" of the computer if it's logged off.
Whoops ... can't edit after ...
No machine has not been rebooted, Yes the Paw Print is in the tray and I'm logged into the Non-monitored Account. Like I said, he's at school and has NO ACCESS to this computer during the day. I even have it timed out during school hours so on days when he's home sick, I have to allow him in ~ Yes, I'm THAT mean mom.
You are not mean at all, just "parenting".
So back to your issue. There are various ways that the product checks itself and it's health to be certain it has not been tampered with, however there have also been scenarios where other products have interfered with that process.
Is this a one time thing or something you get constantly?
Did it start happening around the time we set the clocks ahead?
Matt
Oh shoot ... I wrote those posts thinking I was in the other thread that I started ... well same things apply lol!
I am not receiving alerts in my email (and am supposed to be), but when I log into Norton, I see his activity - up until last night. Now it says "Norton Safety Minder is not running>"
I got on his computer last night since I had a lapse of activity last week when I know he was on a lot. It turns out that he used to logon under his name, now he created a new account under a different name. I did see where an alert was listed that said "New Windows user account(s) were created" I went on and changed the name that he logs in under, but the screen disappeared after I clicked OK. I think that is what turned off the Safety Minder, possibly, because I think it was about that time of night that I see the "Not running" alert.
He has also gotten around the time limitation by changing the time on the computer "PC System time was changed."
He is the administrator since he purchased the computer. However, we agreed to let him purchase it if we were allowed to install a Parental Control just to make sure he wasn't violating our limits on web access after a certain time. Not sure how much of the problems I am having monitoring him are him changing things, or some of the same problems others are having. He told me he has no uninstalled it - since it requires the password I put in. When I saw it on his computer tonight, it said Norton Safety Minder was running, but I see no activity. Also, a few days ago, under his Program listings, it only had the uninstall icon, which he could not do without my password.
Any suggestions?
Well I would say the program is doing the best it can to inform you of what he is doing.
He created a new windows account to get around the one you were monitoring. I would suggest setting his account to be limited so he can no longer do that, or have the discussion that he must not create new accounts as you are notified of those new accounts.
He changed the time on the system to get around time monitoring. I would suggest again that his account should be limited or have a discussion that changing the time is not allowed.
The intent of the program is to keep you informed of what your child is doing, and if they tamper with that (create new accounts, change system time, etc...) it will inform you of that. It's up to you to decide what to do with that information.
Matt
I get this email occasionally and I kept blaming him for somehow disabling it. I know I am the ONLY person that knows the password. I am not at the same address so monitor remotely.
But one day I was using his computer and the message came up without me doing anything related to safety minder - and Safety was still running and monitoring, So for some reason it sends out spurious emails announcing it has been disabled when it has not.
So now I have to believe him, but it would be better if it didn't do it!
Although your are the ONLY person who knows the password, there are many other ways to tamper the system.
For example if your child is set as an administrator instead of a limited account. In that mode they are able to do many things which may cause the system to not monitor properly.
Matt
To anyone listening I also have repeatedly received this message: "Norton Safety Minder on Home used by Matt has been disabled. As you know, Norton Safety Minder is required on every computer monitored by OnlineFamily.Norton." My son is not an administrator and does not have passwords. He claims that this occured during downloading of music from I tunes and does not know how it occurred. I would be interested in having Symantec identify how to eliminate this issue/bug. Alternately are there any other good products out there that people are using ? Thanks
I am having the same problem. Messages saying Norton Online has been disabled. My daughter denys doing anything & I believe her. Looking at the activities report I see that the messages originate 7 minutes after she has logged out on the first occassion, & then the next time it is 30 minutes after her logout. I would guess that this was the time the computer was shutdown instead. Maybe logging out does not register properly with the software.
I also have mobile internet so if the connection is disrupted, this could cause a problem. Can this data not be stored locally & downloaded to your server on the next logon???
I also note that the activity report shows "Logged out of machine" at the time she logged on, not off & no logoff note at the end of her session.
Ok a couple of things here to check.
First is this occurring when the machine is shutdown or put in to hibernation as there may be a problem where we are checking if our services are running when in fact they are being shutdown so they are not supposed to be running and that may be causing the false positive.
Second, other than a false positive as I have described above this is not a bug, but the way the product identifies if a child has tampered with the system. Because they have physical access to the system the product periodically checks its health, and if it sees something that is not right, it alerts the parent.
Matt
So what is the solution??
Thinking about it, I realise in America you are online all the time,. but that is not the situation in other parts of the world. Here is the routine we flow to get on line.
1. Start up windows
2. User logs in (Onlinefamily kicks in fine)
3. User logs on to the internet (All fine)
4. User surfs the internet (Onlinefamily reports back continually, which is fine)
5. User now closes down the internet access, before logging out of their windows account (Onlinefamily can no longer communicate with Norton Server, so remains logged on for that user)
6. User logs out of their windows account (No possible communication with Norton Server, to record this fact)
7. If another user happens to log on to the internet after this, the logout communication can transmit itself fine. (No error recorded)
8. But if no other user connects to the internet after the first user logs out, & the computer is switched off instead, an error occurs.
Does this explain the situation better? How can you solve this problem??
The scenario you describe is not the one that I described.
The scenario you describe works perfectly fine. We are not always connected with the Norton Online Family server, in fact we hold on to some of the data locally for a period of time and send it up in batch. That is part of the reason there is a bit of lag in the time the child does something before you see it on the web site.
Now looking at your specific scenario. Line 5 does not matter. Line 6 does not matter either. The policy is local, only that if an update occurs on the policy it will not be seen until you are online again.
Line 8 does not happen always or does it. We have only been able to reproduce this a couple of times in very rare instances. Can you make it happen every time? If so I would like to see if we can gather some debug logs to determine why yours is happening.
Matt
I am having the same problem, I changed administrator password after I downloaded the program so I know that neither one of the kids knows it. After I installed the program, I went into both kids accts on the the computer and did a couple of things in each account then checked the activity report. Everything was good. I logged off, then logged in a couple hours later and got a report that my son disabled the online monitoring. I have gotten this message everyday since I installed the program. The program stops monitoring it seems randomly, unless there is a hack out there that the kids know about. But when I check the profiles, it says that it's running. I read something about the reboot - does a reboot disable the program? If so that might be how my son does it.
Reboot does not disable it, however there is a timing issue we are looking into that perhaps the tamper protection code is running while the system is shutting down.
What appears to be happening is that during shutdown the services we expect to be running have stopped and then the tamper protection code runs and sees the service is missing. Because of this it sends a false positive about the system being tampered.
We are looking into this issue.
Matt
Matt,
I am seeing a similar issue. I'm piling on here in hopes it's the same problem; let me know if I should start a separate thread.
Safety Minder v1.2.2.2
Norton Internet Security 2010
XP SP3 with IE8
WiFi connected desktop PC (Linksys USB adapter, with an XP hack applied to retain XP's user-switching feature)
Not going into sleep mode (configured for it, but never does for some reason due to running programs)
PC is configured to allow multiple users to be logged in
Typically one child is logged in with browser running, and Switch User is used to login the second child
Grooveshark is a popular site / application left running, playing music while the computer is otherwise idle
I observed the DemonwarePortMapping was installed as an Internet Gateway under XP Networking. It appears to be a legitimate gaming add-on from Activision, but Internet access seems to be running much faster now with it removed.
Kids don't have admin rights, nor a clue what the admin or Safety Minder passwords are.
The event:
Via e-mail, we receive a notice "Client turned off" with text that says "Safety Minder on XX used by XX has been disabled"
However, the activity log online shows the event as "Norton Safety Minder is not running"
Curiously...
The alerts seem to happen on one child's account, but not the other's.
There is no activity in the NSM logs for hours leading up to this event.
We have not isolated a triggering event. In fact it may be happening when the PC is idle (though it never sleeps)
Grooveshark seems to be a very CPU-intensive streaming audio app. Perhaps NSM is seeing internal timeouts during a critical check and triggering a false alert?
Some parental commentary...
* Kids are being taken to the woodshed over what appears to be a bug. Please treat it urgently.
* The inconsistency in your alert messages is a big deal. Your e-mail notice effectively says my kid compromised my password and disabled the agent - that's a huge parenting issue. (The e-mail notice is identical to when the account has been disabled using a password.) In contrast, the online version of the event suggests there's just a tech problem with the agent.
Richard
"Kids are being taken to the woodshed over what appears to be a bug. Please treat it urgently."
I can assure you we are treating the issue of false positives which pertain to this issue urgently. As for taking your child to the woodshed, that is your call, however if you can equate the alert to the time they shutdown or startup, then it's probably the issue we are trying to resolve.
The messages will be updated in our next release for sure, thanks for pointing it out.
Matt
"Second, other than a false positive as I have described above this is not a bug,"
It is a bug, it tells me the service has been disabled, when it has not. A False positive is a bit of code that has not worked correctly and raised an alert when none was needed, either through poor coding or insufficient analysis at the design stage. You are investigating the process that is producing the false positive to fix it, if it's not broke, you wouldn't be fixing it. So please don't patronise us OK!
"kids are being taken to the woodshed"
I must admit when I first saw this message "Norton Safety Minder on X's Desktop used by X has been disabled." I gave my boy the third degree. The wording of the message very strongly suggests that it has detected a deliberate action has been taken i.e. the "has been disabled" part, to stop the service running, and it names the child twice in the message strongly implying they are the cause. When in actual fact, from your answers here you are not reporting the act of it being disabled, rather the detection (or mis-detection) of it no longer running. I think a more honest alert might be more appropriate - something like "Norton Safety Minder on X's Desktop used by X is no longer active.". Only a subtle change in the message, but it takes the focus off it being a deliberate act, whilst still alerting of the problem.
As to the actual instances I have of the Bug...
1. When I got the first alert, I took it at it's word and gave my son a real dressing down that he should NOT disable anything on his computer, which of course he strenuously denied. Then I booted his computer up and tried to disable it myself without recourse to using passwords he didn't know (he leaves the room when I enter passwords) and I couldn't.
2. Second alert arrived while we were both downstairs watching TV, and had been for over half an hour. The PC was left logged on upstairs, untouched. On returning to the PC it was at the Welcome screen (time out rather than logoff), I got back into the session and Safety Minder did appear to be still running.
3. I was sat with my son from boot to shutdown, helping him find things for a project he was doing. We were on for about half an hour, using no more than Firefox and saving a few files here and there. Half way through I heard the alert arrive on my PC. At no point during the session did we receive any error messages and the paw stayed put in the system tray all the way through.
I did boot his PC yesterday during the day and just left it to its own devices for several hours and got no alerts. It could be that this means some activity is needed to cause it, or I was just "lucky" that it didn't alert. I've only had 3 instances of the bug in the last few weeks, so it may simply be that it didn't happen, not that it couldn't happen. I am going to boot his PC during the day a few more times to see if I get the alert.
The false positive is a bug, and that is what we are looking at. What I was trying to say was, if it's not the false positive, then it's not a bug and that the system is behaving as designed.
One thing to note, if the service that we rely on dies (software conflict, file deleted, file renamed, file moved, some type of tamper, or conflict with other software) we can't immediately send the message. The reason being the system is not running. Now if there is a reboot, or the service restarts (which it is supposed to do), the message can then be sent.
Matt