Problem was intermittent throughout the day today, bad this morn, then good all day then bad again when son got home and turned on PC (hindsight). Called ISP and they said no problems on their end (in retrospect they clearly didn't check our traffic as you will see in a minute). Suddenly internet was fast again with no 404s... son came in and said he was running avast boot scan. Soon as scan stopped (avast found nothing) net went to crap again.
Unplugged his PC from lan and ran RKILL (clean), MBAM (clean), GMER (clean), aswMBR (clean), and finally Combofix (yes I know you arent supposed to if you are going to come here for assistance, but I never imagined I'd be here on what 'appeared' to be a clean system judging from the previous 6 tool reports).
Combofix made a couple deletions. I assumed it was good so I rebooted and plugged him in and heard daughter hollaring about internet within 20 seconds. Unplugged lan and ran mbam again (clean) then curiosity got the best of me and I plugged him back in to much protest and ran nirsoft's Network Traffic Viewer. Within 54 seconds it had made 20 round trip connections (incoming/outgoing) to IPs all over the world (checked with nirsoft's IPNetInfo). It is pullin a minimum of 20 connections to external IPs per minute with basically nothing running but OS and AV.
I only had one other tool on my flash and didn't feel like heading back to my pc, so I ran SuperAntiSpyware which found and deleted 6 additional malware, but didn't stop traffic. I am attaching combo fix 'excerpt' (since it was run by this rogue and not at the request of BC)and SAS log. I can also post the Network Traffic logs and IP reports, but I figured I should ask before I posted them pubically, but there are a ton in just a 5 min sample and they are worldwide locations. Alternately, if necessary I can mail those text files if necessary for assistance but inappropriate to post pubically.
Only interesting info from combofix (that I could see) was under 'other deletions':
c:\documents and settings\Pyro\WINDOWS
SAS & MBAM logs attached. GMER was clean and generated empty log. DDS bluescreened PC on run. HOSTS file unaltered. Winsock and LSPs reset (WinsockFix for XP). IE was proxied but I cleared it under Internet Settings...wasn't effecting son who uses chrome.
Thanks in advance and sorry about the premature combofix run, I truly didn't expect to be requiring outside assistance after MBAM was clean