I dissassemble all the files of the Novarg virus and I managed to put a snort rule together that can Identify the virus

alert tcp any any -> any any (msg:"Virus - Novarg"; content:"|26 6a 6f 65 3f 6e 65 6f 2f|"; sid:31337; classtype:misc-activity; rev:1; reference:url,www.cert.org/incident_notes/IN-2004-01.html;)