The way this software worked (as far as I can recall): The installer bundled a DLL from which only a few minor functions were exposed to display offers within the host process. Usually, the only thing the client portion of this DLL needed was a HWND. During initialization, the DLL stored a copy of itself in the user's temp directory. The host application unknowingly then used rundll32 to load this copy as a separate (also elevated) process. This process would run at least as long as the calling process would. Once in place, the process would scan the user's computer for specific use patterns (geoinformation; MS Office presence; what language; etc.). In order to retrieve the latest advertising "offers", the DLL called home with this information over a secure pipe and checked for updates. This data was stored and referenced if the same user invoked the DLL again at some point. Only at this point would any actual targeted ads be displayed in the client application's window.
Things may have changed since then - these were the pre-Windows 10 days - but if it's anything like this, it's wise to avoid the Unity installer.