Had this at the beginning of November (so much for 0-day). Went straight through Messagelabs and McAfee and one person opened it (actually they replied to the email complaining the attachment didn't work).
3 hours downtime while we isolated the workstation and restored from most recent shadow copy (only took that long as DFSr had to be disabled and cleaned).
We were in the middle of migrating to Avast which caught this particular variant.
Good news is much higher awareness of cyber security within the company.