And here is an interesting one... See attached screenshot. Different IP addresses from the same Web Install?????
My guess on this one is that some anti-virus site has been given my EXE to analyze. Sites like VirusTotal.com accept user's EXE uploads or URLs to files they wish to have verified for a virus. My guess is that one of these anti-virus sites is analyzing the contents of the installation package.

When I do a tracert on the IP in question, it traces to google.com It could very well be that Google is checking an email that I sent out to one of its users. The email I sent would have had a direct link to the EXE. I would not be surprised if Google isn't downloading and testing the file for viruses before delivering the email to its users.