Infection vector
Ransom:Win32/ZCryptor.A is distributed through the spam email infection vector. It also gets installed in your machine through other macro malware*, or fake installers (Flash Player setup).
Once ZCryptor is executed, it will make sure it runs at start-up:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun
zcrypt = {path of the executed malware}