OK this is more strange:
We took a NEW user, should be the same as the current one...he can query everything just fine... without any issues.
Is there a way I can compare two windows accounts to see why one is different than the other with privs?
Was the original user part of an AD group where the AD group was denied privs?
That was it, there was an OLD OLD OLD orphaned group that was in the denyreader... wow.
Thank you!