The virus uses a complicated encryption method, which complicates detection somewhat.
Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.
More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.
You may also refer to the Knowledge Base on the F-Secure Community site for more information.
An earlier variant of the Phoenix virus.
A 1302 byte earlier variant.
A 1701 byte variant.
So-called "M" and "D" forms of the variants have been reported, but this is actually a misunderstanding. The "D" form is just the decrypted virus and the "M" form is a sample file infected multiple times.