Why does it only redirect some of my site visits ? : The hackers have adjusted files on your website to perform different actions depending of the device, the browser used by the visitor , or the location the came from ?. Their aim is usually to dispatch their virus to the certain visitors that are vulnerable to their new nasty concoction. If the user is vulnerable the silently infect them . If the hacker finds it cannot affect that visitor it is redirecting these users to Bitcoin.org. So actually the users that are redirected to Bitcoin are the lucky ones
Why should I care that my business is infecting my visitors : Your business websites activity will be spotted as a malicious site and Google and the other major search engines will blacklist your website from the public.
Why are they redirecting to Bitcoin.org ? : Yes good question!. Usually they redirect you to an attack site to fully take over your PC. So why to a valid site such as Bitcoin which currently seems free of infection ? . Our best guess at the moment is they are trying to give visibility / promotion to this new form of currency
We found a hacked file and removed it. Are we now clean ? : Imagine you have a bad illness and you take a couple of very powerful painkillers. You feel great for a bit ! Are you cured ? Well experience lets you know that those pills will were off soon and you will feel terrible again. So you wisely head off to the doctors to get the proper cure. This is a very close analogy to fixing hacked websites. You find a hacked file (for example and adjusted .htaccess file) and wow your site seems fixed! Your managers love you and everyone celebrates. But this quick win shortly wears of when you find out that a day or week later your site is hacked again and this time even worse!. What has happened here is that you removed about 1% of the hack. The visible part. But the real nasty parts of the hack were left hidden away on your site. This malicious software is activated again on your site within seconds when the automated hacker bots return. In summary you need to remove all of the hack!