Primarily, IF something were to infect the computer while logged in as an admin user, whether it be a hacker or malware, the privileges given to the infection may be those of the logged in user.. Still, it's possible to lock down certain items even when logged in as an admin. Use complex passwords on all logins, including the hidden "administrator" which is available only from Safe Mode. Be cautious about scripting an ActiveX in websites.. Block them if needed.. Block popups.. Use a secure browser. Use safe practices with your email. Don't visit "dodgy" websites. Don't use P2P downloading software. Keep third party programs, as well as Windows, up to date with Critical Updates, etc..
Yes, a current antivirus and antispyware program helps.. So does an effective firewall. . But the primary force for preventing such attacks is YOU, the user..
Personally, I run all my computers as an administrator.. Then again, I don't let any of my employees do so.. It depends on the situation.
Hope this helps.
Grif
It has just come to my attention that running a PC in administrator mode is a mortal sin, very risky, when PC is connected to a hi-speed DSL modem, regardless of whether an internet browser is open or not. Is this really true?
I have been doing this for 3 yrs, since I bought my Dell desktop, Windows XP. It annoys me that I just now discovered this; there should have been a warning or popup from Dell, MS or Windows XP, when initially turning on and setting up. I suppose I should have thoroughly read the Dell owner's manual, after I incorrectly did the set up and connected to internet to print the manual. This topic is buried more than 100 pages therein.
If this is really so critical, is the danger related to both hackers and viruses/malware? Doesn't an active antivirus pkg protect it?
Desn't an active firewall offer necessary security?

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic