We created a rule to block qbot* creation of folders/files in AD and also with policy in SEP it did not help the first day but after a couple of days most of the viruses have vanished.
The files have been submitted to Symantec since we have the default settings with submissions in the antivirus policy. I am not sure if the updated signatures since then has had any impact in catching the virus.