I just re-read the entire thread. I was struck by two things:
- This PC was once on a domain.
- This PC had trojans.
I am aware you reconfigured the PC to change it from Domain to Workgroup, but there still might be something in the profile that is searching for something on the domain. I suppose you could create a fresh profile, but I'm not sure I'd waste my time since...
I believe the PC is still compromised. Malware can sometimes be VERY tricky to remove. Sometimes it might APPEAR to be gone, but there will still be a nasty, almost-impossible-to-detect rootkit present (or maybe even a "bootkit" hiding out in the boot sector). The symptoms you describe certainly indicate the presence of malware; the PC might very well be a part of the "botnet" right now.
I recommend that you make sure all the data is backed up and nuke the drive and start from scratch. It's a hassle, but it would probably still be the quickest (and surely be the most effective) way to deal with this mess.
If you had unlimited time and wished to experiment and explore (but I believe you said this PC belongs to a friend), you could search the web for Process Explorer tutorials and start a thread on Bleeping Computer or a similar site to get guided help. But I truly think you'll be better off if you flatten and rebuild.
Good luck and Happy New Year!