I haven’t had this happen personally, but are you allowed to edit your hosts file? I’m assuming those IP addresses are coming from DNS resolution, and if you hardcode those DNS entries to resolve to 127.0.0.1, it’ll stop the ads.
nslookup <ip address>
should give you the domain names, if not there’s DNS logs in Event Viewer that should tell you.
Even if he didn’t directly participate, did he witness it? Turn a blind eye? I hope future reporting is clear what it is and is not evidence of, but I also hope people ask the very reasonable questions that follow from what we do know now.