This is a tough one. Is it isolated to any particular client or server computers? Are there any events tracked in system event logs that can guide you into online research? A good tool for watching a system during the event is the Sysinternals <a href=”http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx”>Procmon</a> utility. Can you disable AV and see if the issue happens? There have been instances of bad AV updates creating such problems. You may need to open a case with McAfee if you see that AV is creating the problem. Is AV managed through EPolicyOrchestrator? Maybe move some of the machines into different groups and have updates and or other AV events at staggered schedules. If all clients update AV at the same time, you will see some issues.
Let us know how you get on with diagnosing the event logs and any other details you can offer. We will be glad to assist further.