You should be able to just click on the Edit button, select the account, and then click on the Remove button in explorer. The "(OI)(CI)" in the icacls output indicates that that entry will be inherited by all files and subfolders. You should only need to remove it in this one spot.
You should be aware that Windows has "capability SID's" that do not translate to a friendly name.
I recommend that you do not touch the permissions on either of the Program Files folders, the ProgramData folder and any folder under c:\Windows.