When the virus is run, it will install its macros and infect every document run.
When an infected document is run on December 6th on any year, it displays a message for a split second before rebooting the computer. It adds the "NoDesktop" and "NoDrives" to the registry so when the computer reboots, no desktop is seen. When the user examines explorer.exe, it has removed all drives.
The message is supposed to be in Chinese and is translated to "Microsoft products have a lot of vulnerabilities, Don't use Microsoft products from now on".