Just to make sure ,are the Machines (servers, workstations & notebooks) are patched up alright ?
especially against this one MS06-040
http://www.microsoft.com/technet/security/bulletin/MS06-040.mspx
this bug seems to be all the rage now, an exploit went public among Malware coders and quite a few threats were released to the wild exploiting this vulnerability, symptoms include repeated service crashing, hidden download & execution of other malware.
until this clears up & you ensure all machines are patched up , try removing any exceptions for windows firewall for file & printer sharing.
Also what does eventviewer say when services crash ?
finally it would help alot if you could post a hijack this log from one of the infected DCs