EtreCheck was an excellent suggestion. It appears she has at least two bits of malware. The primary offender just happened to infect on the same day as the security update.
Adware:ⓘ
/Library/LaunchDaemons/com.centripetencyUpd.plist
/System/Library/Frameworks/VSearch.framework
2 adware files found. [Remove]
Unknown Files:ⓘ
/Library/LaunchDaemons/com.snock.plist
/etc/snock.sh
/Library/LaunchDaemons/com.urothl.plist
2 unknown files found. [Check files]
This snock thing is the primary offender as it appears to be only partially in place and is sending all port 80 traffic:
Sues-MacBook-Pro:etc sue$ cat /etc/snock.conf
rdr pass inet proto tcp from en1 to any port 80 -> 127.0.0.1 port 9882
pass out on en1 route-to lo0 inet proto tcp from en1 to any port 80 keep state
pass out proto tcp all user Monandria
Now to do some scrubbing.