I think there's an option to exclude OpenCandy from the download (or during the installation). If you still don't trust the installer, try running it sandboxed. (using sandboxie). Once the installer is finished running, you can explore the sandbox, find the actual CDBurner installer and copy it out of the sandbox. (then, just delete the sandbox, which will delete all the other junk it tried to install). I always do this with installers I don't trust.
P.S. I just checked their download page. In tiny text, under the "Download Latest Version" there's a "more download options" link. Click that, and you'll see a specific download link that does NOT include OpenCandy.