Yep, it’s called browser poisoning and you don’t have to download anything. It’s a “driveby” download (not unlike the mainstream media and their brainwashing)
I like to use combofix in conjunction with malwarebytes.
Sometimes you have to rename the .exe to .com to trick it into running in safe mode with networking.
I had to use hijackthis to find the crap and killbox to get it before it re-spawned. I had one called Aurora a couple of years ago. It would just rename its files on restart. Vaguely remember using about five different programs to get everything.