Since an infected computer operates with the permissions of the user currently logged on, it can only traverse and encrypt files it has read & write access to. If a user does not require read/write access to various network shares, consider removing, at a minimum, write permissions from the locations that are not required to be accessed by users for a routine business need.
File server : user permissions
NTTAN
CONSIDER DISABLING FLASH
While disabling Flash won’t remove all risk from Internet activity, it will decrease the number of well-used infection vectors open to attackers.
Browser
HelpDesk
CONSIDER DISABLING WINDOWS SCRIPTING HOST
This can be centrally prevented via Group Policy. Create the following registry key and value:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Script HostSettings Enabled and set the ‘Value data’ field of Enabled to ‘0’ (That is a zero without the quotes).