Clients update from the Management server (Domain controller).
That is normal for the clients to do so via VDTM, but when they launch LiveUpdate, they either will go to a Symantec LiveUpdate server, or to an internal LiveUpdate server (LiveUpdate Administrator).
My thought is if some change was implemented on the SAV server preventing the distribution of definitions, and the internal LUA (if in use) is also failing to update, then this situation might occur. Does the SAV server itself show that it's updating?
Virus definition corruption can also cause this, but it would surprise me if it happened to so many computers at the same time. It really suggests something environmental.
sandra