I don't think you can outright deny them read rights to the C: drive, at the very least they need execute rights to %programfiles%.
If you're worried about them messing (editing) system and program files, I imagine giving them limited user accounts should have solved that.