@venustus
1- First using a Admin account by default is not recommended. Use SUA.
2- once done, set UAC to Max, if not , don't bother enabling it. "default" doesn't help much more.
3- implement password for UAC prompts on the admin account.
4- block unsigned elevation.
With just those little steps, you just thwarted 80% of the common malware (without even needing an AV).
Now if you expect to cross upon sophisticated malware, it won't suffice (obviously) but still help.
You think security or you don't. don't take half-measures.
I'm not sure. It seemed like people who are tech illiterate is more likely to accept uac warning in case of malware infection. So how could it be more important than a full functional security software? Is there anything I'm not aware of?
yes obviously.
Google about Integrity Levels, session 0, and admin/system privileges.