Not true. You can spoof a MAC address in software.
Irrelevant. The router's mac is in the TCP header, spoofed or not. The mac of his own computer is not in the TCP header. Proves nothing either way. The only thing that matters here is whether his computer was hacked and remotely controlled to download child porn. That's not very likely.