Many midinfecting viruses leave one or more tell-tale signs in their infected files, which can raise suspicion and increase the chances of heuristic detection. These include a writable code section, unusual imports, cross-section jumps and a large block of encrypted data near the end of the file. The authors of Mal/Xpaj-B have gone to considerable effort to avoid all of these.
Link -
Mal/Xpaj-B - how to avoid looking like a virus | SophosLabs blog