The second session of ctf.360.cn, reverse part of the third question of writeup--
Topic: see attachment
This problem is the quickest to solve, and the tip is very clear.
There was an error in the direct operation of exe. When OD was opened, it was found that the entry point was a jmp.
F8, tracked to the address after jmp, found the cause of the error in running the program.
In fact, this topic is to simulate the behavior of virus infecting exe, modifying file entry instructions, and inserting malicious code.
Patching is actually finding the code of the real entry function header and nop the previous instructions such as jmp. (it is also OK to modify OEP)
Attachment: http://down.51cto.com/data/2365126