What's most worrying about this is that Dropbox is injecting itself into processes like NotePad++ and Firefox that have nothing to do with shell extensions.
Either this is lazy coding, or there is some malicious intent to spy.
The best cloud security solution is one where you control the encryption keys AND stuff is encrypted on your device BEFORE uploading to the cloud.
We tried SpiderOak but the security was hard for our users. We ended up using Syncdocs which encrypts Google Drive. It lets our team share and use Google Docs normally, but secure folders we need to keep encrypted. They also disclose their AES encryption source.
It makes like a bit more complex, but PGP can be used for mail and here's how to protect GDrive files: https://news.ycombinator.com/item?id=6644888
Remember these revelations date from a year or two ago, who knows what they're up to now?