I know Tiger Shark is a snort user but I was wondering if anyone used the rules I had developed for the original Novarg virus? I tried to develop them to still function even under virus mutations.

What really should trigger on all these viruses though are the UPX rules I posted here. All these current viruses are still using UPX to hide the exe. And like Ive said before UPX is BS, its made specifically for trojans and virus writers to hide there exe's. While the UPX's rules do generate some false positives it has been 100% effective in triggering on true UPX viruses.