When do encryption viruses run?
From my experience ONLY.
Are they just running in the background, before they decide that it's time to reveal themselves?
Yes, they run in background and they make encrypted and hidden copies of all the files.
Doesn't the user see the damage before being told about it?
Not so much! Maybe they can experience some performance decrease when the encryption takes place.
Why the user doesn't expect a thing?
They make a hidden partition in which they make copies of encrypted files and then the format the main partition copy all the encrypted files and delete the hidden partitions.
How did I recover my files? In my case they used Bitlocker (no TPM) as an encryption tool and I applied the old technique of mounting the HDD (Elcomsoft Forensic Disk Decryptor).
Short answer of how they work:
Infect
Encrypt and hidden copy
Replace original with copy
Restart
Display message