apparently the modus operandi of this trojan is that it looks in your RECENTLY USED record and encrypts that first, thinking that you probably use the important files more often, and they might be important enough that you would pay a ransom to have them decrypted.

When I searched my computer for files named HELP_DECRYPT, I notice they were all time stamped at practically the same time. Does anybody know of a utility that makes a record of the date, time and name of any program that writes to the hard drive? If I could determine which program was writing at the time the files were changed, I'd have a chance of deleting the right thing.