Viruses that encrypt your files, like the recently very common 'Locky', seem to perform a lot of work before they are 'done'.
I wonder, when do these programs run? They must take quite some time, because they obviously have to read/write a lot of files. Also, they might want to delay showing their presence to the user, so they can encrypt more files before being discovered.
Are they just running in the background, before they decide that it's time to reveal themselves? Doesn't the user see the damage before being told about it?
edit: I would not consider this to be a duplicate, since I was asking when this takes place, not so much how.