I was reading about this the other day. There are actually 3 versions. One directed at porn sites, one at music download sites, and the other at sites for drivers/OS upgrades.
If you are ever locked out of taskmanager in a normal boot by a virus, you can kill these by doing a safeboot and then running msconfig.exe and killing the processes that are listed from unknown providers. Then rename and delete the executables that have weird names and time stamps when the virus began. These will be in the startup applications list, but you should do a search of the entire boot drive.
While in msconfig, you should also delete any files in your internet temp directory with time stamps around the time of infection.
Start - Run regedit (type it in the box)
HKEY_CURRENT_USER - Software - Microsoft - Windows - CurrentVersion - RunOnce and Run are also favorite hiding spots for this sort of nonsense
Bump for reference.