Let's move this to a productive conversation though. What can Microsoft do, as an alternative, that doesn't result in an identical or worse situation?
Giving out free code-signing certificates also makes it easier for malware to get legitimate certificates. This is akin to LetsEncrypt for certs -- https://yourbank.real-secure-website.xy can have a valid cert but it doesn't mean it's legitimate. What's the equivalent to the "URL bar" for software? What's the equivalent to the ACME domain validation challenge?
The SmartScreen stuff is another attempt at this -- software that's not frequently seen is flagged as a potential problem. As a developer, this annoys me greatly. As the de-facto support person for family that don't understand computers... I don't mind so much. Without this, malware gets executed directly and now you're dependent on (very imperfect) anti-virus software.
I guess the Store is another way to have "trusted" applications, but you only have to look at the Google Play or iOS store to see how well this ultimately works out (for both malware and legitimate authors).
Note this isn't even about admin vs non-admin installations. Obviously malware running as admin can do more damage that's harder to recover from, but non-admin malware is just as capable of doing bad things (think: stealing credentials, running cryptocurrency miners, ransomware), and after being hit by a randomware attack I doubt your "typical" user is going to really care much about the distinction between their account vs the entire computer being trashed.