Those connection logs prove nothing.
You know, the old "You haven't proved that it doesn't exist so that means it does" is a logical fallicy so old it's named in latin.

(Argumentum ad ignorantiam)
Have you looked at the whole request headers and URLs? What about POST data?
the only keys appear to be gbatemp's referral key, a NONCE or two for some session stuff, things of that nature.
Note that those things aren't shown in the screenshots.
If you'd like, I can go and grab all the info and post it in a big-ass spoiler, I just did a screenshot of the main output to show...
A - I actually ran a log.
B - I ran it more than once it and the program tried to get more than one piece of software.
C - It sends out referral key data and tries to grab installer files in return.
I see some URLs containing lotsa data, like the "/pinger" thing. It's informing them of what are you exactly doing on real time. Certainly looks like spyware.
So if the bank has cameras inside it, they're spying on you?
As far as I see, the only data transferred is data directly related to your use of the program while it's running. Are Chrome and Firefox spyware because they collect usage statistics too?
If it can be shown that these programs are actually digging personal (that is,
identifiable and private) data out of the user's computer (that is, data that existed outside of this program beforehand) and sending it, then it's spyware.
As far as I can see, however, it's just adware.
Also it seems it's offering to install incredibar and babylonTB.
Yeah I don't like the shit it wants to install either.
EDIT: Small correction to my list of reason to run it.