New year, same old threats, same old countermeasures.
If you're working today, do yourself a favor and read up on Windows event logging. Increase the size of your security logs dramatically and enable at a minimum:
* Process tracking (with arguments)
* Share access auditing