Norton High CPU, Memory or Disk Use: Measure the Spike Before You Fix It
A busy scan and a security service stuck at high load aren't the same problem. The safe workflow is to capture the process and trigger, let legitimate work finish once, update and restart, then repair only if the same idle load returns.

Quick answer: open Task Manager, sort by CPU, Memory and Disk, and observe ten quiet minutes after startup. A short Norton spike during an update or scan is expected. If the same Norton process remains high while the PC is otherwise idle, note its name, Norton build, Windows version and trigger; restart, update Windows and Norton, allow one controlled scan to finish, then use the supported repair/reinstall path. Don't permanently disable protection or delete drivers by hand.
Normal Norton work has a beginning and an end
Antivirus software must read files, unpack archives, compare reputation data and inspect activity. A first full scan, a large product update, a new game library or a download folder full of archives can raise CPU and disk use. On a laptop, that can also wake fans or shorten battery life. The load isn't automatically a defect if it falls when the task finishes.
A stuck state looks different: one Norton service or NortonUI process remains elevated while the machine is otherwise idle, returns after a restart, or repeatedly wakes a discrete GPU without a visible task. Current May and June 2026 reports describe those patterns. They establish that the failure exists on some builds and machines; they don't establish a normal Norton percentage or a population-wide rate.
| Pattern | Likely interpretation | Next action |
|---|---|---|
| Spike during update, then quiet | Expected maintenance | Let it finish and record duration |
| Heavy disk during first full scan | Expected file reading, worse on HDD | Finish once; retest later |
| High CPU at idle for 10+ minutes | Needs diagnosis | Record process, build and trigger |
| Load returns after every restart | Update, conflict or damaged component possible | Update, isolate overlap, repair |
| GPU stays awake for NortonUI | UI/graphics assignment or build issue possible | Record GPU engine and app build |
| 100% disk plus storage errors | May not be Norton alone | Check drive health and Windows logs |
Measure ten quiet minutes before changing settings
Restart Windows, sign in and wait for the desktop to settle without opening a browser or game. Press Ctrl+Shift+Esc, select Processes, and sort by CPU. Repeat with Memory and Disk. Expand the Norton group so the exact service is visible, then note whether Windows Update, Search indexing, a browser updater or another security tool is active at the same time.
One Task Manager screenshot can capture a transient peak. A useful record has a start time, ten-minute observation, process name, peak, steady range and trigger. Open Norton and record the product build and whether a scan or update is running. If the computer is hot, also check clock speed and power mode; thermal throttling can make an ordinary workload feel much worse.
Intel's high-CPU troubleshooting guidance similarly starts by identifying the process and reducing unrelated background work. Resource Monitor can add file and disk details, while Windows Reliability Monitor shows whether the spike began after a product, driver or Windows update.
Current lab results and current complaints can both be true
Norton earned full performance marks in the current AV-TEST Windows consumer cycle and performed strongly in AV-Comparatives' April 2026 low-end-PC test. Those controlled results are a strong reason not to describe every Norton installation as inherently heavy.
They can't rule out a version-specific fault, unusual driver, broken update or a workload outside the benchmark. PCWorld's April review found relatively little background effect but more visible impact during sustained scanning on a modest laptop. A current Norton Community thread dated May 27 reports constant high CPU after an update, and June Reddit reports describe 30% idle CPU or discrete-GPU wakeups. The responsible conclusion is “good typical test performance, real outlier failures,” not choosing one dataset and hiding the other.
What usually explains high CPU, memory or disk activity
Scan or update work
First scans, new signatures, product upgrades and large changed folders create legitimate bursts. Let one controlled cycle finish before judging idle behavior.
Two security layers colliding
A second antivirus, old web shield, VPN filter or leftover driver can make both products inspect the same traffic and files.
Damaged component
An interrupted upgrade or corrupt install can loop a service. This is the case for supported repair or reinstall, not manual registry deletion.
Browser and download trigger
A security extension, large download, archive extraction or many changing cache files can keep inspection busy. Test the trigger rather than disabling every browser protection at once.
Slow or failing storage
An HDD, low free space or drive errors can turn normal scanning into long 100% active time. Check storage health before blaming the only process reading it.
Malware or unrelated Windows task
The visible Norton process may be responding to activity elsewhere. Verify the full process list, Windows updates and scan results.
Safe fix sequence: change one thing, then retest
- Capture the baseline. Save process name, build, Windows version, timestamps and whether a scan or update is visible.
- Restart normally. A true stuck state often clears temporarily; that result is useful evidence even if it later returns.
- Update both layers. Apply Norton LiveUpdate until no product update remains, install supported Windows updates and restart again.
- Let one controlled scan finish. Schedule it while plugged in, record its duration, then observe ten idle minutes. Don't keep cancelling the same scan and force it to start over.
- Test the trigger. If load begins with one browser, game launcher, archive folder or VPN connection, reproduce only that condition and record it.
- Inspect overlap. Confirm Windows Security names the expected antivirus provider and remove abandoned full security suites using their supported uninstaller.
- Repair, then reinstall if needed. Use Norton's official account and support tools, restart when requested, update and repeat the identical baseline.
Don't turn off real-time protection for the rest of the week to prove Norton was involved. If a short diagnostic disable is explicitly requested by official support, disconnect from risky activity, time-box the test and restore protection immediately. Ending protected services or deleting drivers by hand can create a worse problem than the original load.
Check Microsoft Defender and leftover security software
Windows normally registers one primary real-time antivirus. When Norton is active, Microsoft Defender Antivirus should move into the appropriate compatible state rather than run a second full real-time engine over the same files. Open Windows Security → Virus & threat protection and confirm the named provider; don't force Defender services through registry hacks.
Old VPNs, firewalls, browser shields and partially removed antivirus products can remain even when their main window is gone. Use Installed apps and the vendor's supported cleanup tool where necessary. If the issue started after adding another security product, remove the newer change first and retest. Our Defender versus Norton guide explains the replacement choice if you decide to keep only the built-in engine.
When a supported repair or reinstall is justified
Repair is reasonable when the same abnormal process returns after restart and updates, Norton shows an error, or the issue began with a failed product upgrade. Save the account login and subscription details, close work, and enter support from Norton's official domain. Avoid third-party “Norton repair” downloads and support numbers in search-result PDFs.
After reinstall, don't judge the first five minutes: the product may update and build its initial state. Let that complete, restart and repeat the same ten-minute idle baseline. Verify that Norton reports protection on and that Windows Security recognizes it. If performance improves only until the next update, keep both before-and-after build numbers.
Give support evidence they can act on
- Exact Norton plan and build number
- Windows edition, version and latest installed update
- CPU, RAM, storage type and whether the laptop is on AC power
- Process name and CPU/memory/disk range over ten minutes
- Whether a scan, LiveUpdate, browser, game, VPN or restart triggers it
- Steps already tried and whether the result survived another restart
Don't post product keys, email addresses, payment details or full diagnostic archives in a public forum. A current Norton Community high-CPU thread is useful for confirming a similar 2026 symptom, but your support case still needs the local build and trigger.
When replacing Norton is the rational fix
Switch when sustained abnormal load survives current updates, a supported repair or clean reinstall and the same controlled retest—or when support confirms an unresolved defect in the build you need. Also switch when the subscription's broader bundle no longer earns its renewal price. Don't replace it solely because Task Manager caught one update spike.
Use our Norton alternatives guide to choose by reason, then trial the candidate against the exact boot, browser, file-copy and game workload recorded here. Our full Norton review provides current performance context, and the cancellation guide keeps software removal separate from billing.
Norton performance FAQ
Why is Norton using so much CPU?
Short spikes can come from updates, a first or scheduled scan, archive inspection, downloads or browser activity. Sustained CPU use while the PC is otherwise idle can indicate a stuck scan, update problem, overlapping security software, damaged installation or a version-specific defect. Measure the process and trigger before changing protection.
How much CPU should Norton use when idle?
There's no universal safe percentage because processors, power modes and background tasks differ. The useful test is whether usage returns near the machine's normal baseline after Norton finishes work. Record ten quiet minutes after startup and compare the same workload across restarts.
Can I end Norton in Task Manager?
Don't use End task as a permanent fix or disable core protection services blindly. Protected services may restart, and forcing them closed can leave an unclear security state. Record the process, restart normally, update the product and use Norton's supported repair or removal route if the load remains.
Why does Norton use high disk during a scan?
A scan reads many files and can create heavy disk activity, especially on an HDD, during first scan, archive inspection or after a large update. It becomes suspicious when high disk use continues well after the task ends, repeats indefinitely or appears with storage errors and system freezes.
Does Norton slow down a PC in 2026?
Current independent results are generally good: Norton earned full performance marks in AV-TEST's current Windows cycle and performed strongly in AV-Comparatives' April low-end-PC test. Individual systems can still experience slow scans, update bugs, driver conflicts or sustained resource use.
Will reinstalling Norton fix high CPU?
A supported repair or clean reinstall can fix damaged components, but it should follow a restart, updates and a measured retest. Save the product key or account access, use Norton's official tool, restart when requested and verify both protection and idle resource use afterward.
Can Norton and Microsoft Defender run at the same time?
Windows normally places Microsoft Defender Antivirus into a compatible passive or disabled state when a registered third-party antivirus is active. Check Windows Security for the registered provider. Don't install or force two full real-time engines to scan the same files.
When should I replace Norton because of performance?
Consider switching when sustained abnormal load survives updates, a supported repair or reinstall, and a controlled retest, or when Norton support confirms an unresolved issue affecting your build. Trial the replacement on the same tasks and compare medians rather than one screenshot.
Bottom line: temporary work is normal; repeatable idle load isn't
Norton performs well in current controlled benchmarks, so one scan spike isn't proof that the product is inherently heavy. Sustained idle CPU, disk or GPU activity that returns after restart deserves a methodical diagnosis. Measure, update, finish one controlled scan, check overlap, repair and verify.
If the same problem survives that sequence, changing products is reasonable. Keep one real-time engine active, compare the same workload and cancel billing separately from uninstalling the software.