Replace the hardcoded "c:\\program files" / "c:\\windows" prefix
heuristic with a PathResolver::requires_admin method that matches
against runtime-resolved FOLDERID_ProgramFilesX64,
FOLDERID_ProgramFilesX86, and FOLDERID_Windows. Honors the MVP
"no hardcoded paths" rule, catches Program Files (x86) explicitly,
and works on non-C: Windows installs.
Match logic uses path-component boundaries so "C:\\Program Files
Custom" no longer false-positives against "C:\\Program Files".
Adds unit tests for the new method via a #[cfg(test)] constructor
that lets us seed roots without invoking Win32.