Okay, I see what you mean by using mode ab
but unfortunately, it’s not quite as simple as you think it is.
I’ve already documented a method for this in my paper PE File Infection and have done an analysis on a simple appending virus Understanding a Win32 Virus: Code Analysis with background material Understanding a Win32 Virus: Background Material.