Earlier quoted context omitted.
You may be surprised to learn that removing admin rights is no longer (and never really did) protect against app installs. Many developers have figured out they can just install into the user’s profile. Only apps that truly need admin rights (that install services, etc.) would be blocked. Everything else is wide open. The admin rights restriction on app installs was almost just a convention that people followed. Now…
Note however this is only partially true for single user devices, where lack of admin rights does prevent some attacker persistence, and is not at all true for multi user devices e.g. the shared family PC.
Persistence is easy enough with startup shortcuts or scheduled tasks in each profile.
Also, I’m not saying these apps have some kind of hidden malware, I’m saying they are operating as designed, and usually offer features in exchange for letting them do things like upload your address book, etc.