if your visitors use Norton Internet Security/Norton Personal Firewall
in such case
instead of [HTTP_REFERER] => http://your-traffic-source.com
you get something like [HTTP_WEFERER] => CJVTLBXFGGMEPYOQKEDOTWFAOBUZXU
so your logs count a hit but the ref-source cannot be identified
do you know any other firewalls that block refs from being sent?
more info