It looks like the Antivirus providers are coming up with the Sig's for this threat.

When a user visits a Web page exploiting the Microsoft Internet Explorer Drag And Drop File Installation Vulnerability with Internet Explorer, the browser may download a file named windows-update32.exe to the Windows Startup folder. This file is a copy of Backdoor.Sokeven.
My Symantec updated last night.

