Temp;System Volume Information;pagefile.sys;hiberfil.sys;winsxs
UsrClass*.*;ntuser*.*;Windows Defender;$recycle.bin
Temporary Internet Files
C:\ProgramData\Microsoft\Windows\SystemData
C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore
C:\ProgramData\Microsoft\Windows\AppRepository
C:\ProgramData\Microsoft\Windows\LocationProvider
C:\ProgramData\Microsoft\Windows\Sqm
C:\ProgramData\Microsoft\RAC
C:\ProgramData\Microsoft\User Account Pictures
C:\Microsoft\Windows NT\MSFax
C:\ProgramData\Microsoft\Windows NT\MSFax
C:\ProgramData\Microsoft\Crypto
C:\ProgramData\Microsoft\Network\Downloader
C:\ProgramData\Microsoft\Search\Data
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics 
C:\ProgramData\Microsoft\Windows\WER
C:\ProgramData\Norton
\AppData\Local\Microsoft
\AppData\Local\Microsoft\Windows Mail
\AppData\Roaming\Microsoft\Protect
\AppData\Roaming\Microsoft\Windows\Cookies
\AppData\Roaming\Microsoft\Windows\IETldCache
\AppData\Roaming\Microsoft\Windows\PrivacIE
\AppData\Roaming\Real\rnadmin
\AppData\Roaming\Skype
C:\Microsoft\Network\Downloader
Master.vzdb
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
C:\ProgramData\Microsoft\RAC\StateData
C:\ProgramData\Microsoft\Search\Data\Applications\Windows
C:\ProgramData\Microsoft\SmsRouter 
C:\ProgramData\Microsoft\Windows\LfSvc