Once started, the Popcorn Time ransomware will check to see if the ransomware has been run already by checking for various files such as %AppData%\been_here and %AppData%\server_step_one. If the been_here file exists, it means the computer has already been encrypted and the ransomware will terminate itself. Otherwise, it will either download various images to use as backgrounds or start the encryption process.
So, everyone should just make sure %AppData%\been_here and %AppData%\server_step_one exist?
Find out what works in your organisation, and evolve incrementally.
Hm, sounds like agile to me.
Never make anything simple and efficient when a way can be found to make it complex and wonderful.