Did some digging. The IP addresses in question (204.177.92.0-204.177.93.255) are run by a company called Lexitrans
Tracked down some intersting stuff on some techie message boards about these guys. It seems they take existing dialer programs, and modify them with all sorts of stuff. If you see it installed on your PC, you just assume it's from mtree.com or goin.com, or any other site that runs dialers.
If you already have any of the dialer programs in your PC, this exploits them and installs itself over them without you even knowing. They can then do all sorts of nasty stuff.
BTW, on March 18th, Lexitrans was indicted for money laundering :
http://stacks.msnbc.com/news/887174.asp
You see ebus, a litle research and digging goes a long way. You should do that before you blame CCBill or Corina on a public board for what is most probably embedded in your system.