My wife's computer was recently compromised and I have tried to clean it.
I installed Microsoft Network Monitor to see if there was any unexplained internet traffic and I noticed a connection to Dropbox. Here is the given details:
URI: /subscribe?host_int=34404476&ns_map=162130732_8752065324,26351085_36339744642541,129513375_382381602719&user_id=16845707&nid=0&ts=1386575431 Host: notify8.dropbox.com Process Name Dropbox.exe Note, neither myself nor my wife use Dropbox. I checked the install date for the instance of Dropbox that is on her machine and it has an install date of May this year, so this was probably not installed as part of what ever virus etc. infected the machine.
I tried to do a reverse lookup on the IP 108.160.162.115 and I got nothing.
Does this look like my wife's machine is trying to connect to a particular Dropbox account to retrieve some software (possibly malicious)?