Once they find the exe or msi of their choosing is found they quickly double click on it and answer yes to any prompt that comes up regardless of whether it asked for admin rights or to sell their kids to a veal farm.
Fortunately they have an antivirus to catch them if they do anything stupid. Unfortunately so do malware authors who will carefully craft their wares to bypass such protections while the antivirus will spastically check every file that is opened and everything the computer wants to do before it lets it do it catching only the dumbest malware while ruining performance.
Meanwhile Linux users can get all or virtually all software from a single app store which actually contains all or most of what they need. Not installing malware remains a vastly easier solution than trying to contain malware you are stupid enough to install.
... less secure than Haiku, the OS that runs everything as root?
> with limited sandboxing
With limited default sandboxing (snaps, flatpaks), and assorted add-on options (firejail, bubblewrap), in which respect it's... exactly like NT (sandboxie) and Darwin?
> and no provision for checking binary signatures
I am aware of no package manager which fails to check signatures before installing. They may exist, but at least the major players do.
[citation needed]
> limited sandboxing
seccomp? Namespaces? What exactly do you want Linux to be able to sandbox that it can't?
> no provision for checking binary signatures
Bootloaders already enforce this for the kernel, and the kernel can enforce it for its own modules. Userlands are free to enforce it for userspace programs (e.g., how Android requires APKs to be signed).
Either way, Windows compromises all of your data nonetheless. So not only are you actually getting viruses, your data's stolen anyways. Compare that to Linux, where viruses aren't as frequent and no ones siphoning your data. In the end, who's better off?