I have to admit I have doubts about the security benefits of running as a standard user.
Since malware can install itself into a user folder without the elevation prompt appearing, it seems like the hoped for security benefit is lessened. The fact that the malware would be limited to just the one account still gives it access to usernames, passwords, credit card info, that is entered into that account.
I am aware that the malware cannot make system wide changes, but it could also just wait until the next rights elevation occurs, and then do it's dirty work at that time.