I can confirm this.
The links on mega from the thread are replaced and contains a rarfile with an exe dated to 11 April 2017.
(Which is to young and no longer the original old 2016er wallet!)
The .exe installs an file "explorer.exe" in C:\Program Files (x86)\WindowsClient\explorer.exe - which is a fake.
To activate them, it created an autostart entry in the registry that points directly after boot to this file.
When try to kill the process, the process is spawned many times and restarting in endless loop.
At this point a immidiate power-cut from the machine is best what you can make at this moment.
For me it looks like an replacement for the regulary explorer - which contains keylogger and all the usual
things we know.
I had the chance to remove all instances fast enough, before the usual "download actions" begans.
Antivirus has not detected any activity - only the long starting time and nearly doing "nothing" for
about 30 Seconds makes me fast checking all running processes and shutdown the machine asap.
By the way: On the old website the other download-link is dead to mega, further more, most google
searches to the forum opening post - so this thread needs immidiatly disabled or edited by an admin.
thanks for the heads up