Great questions. I'll give my 2 cents based on what we've witnessed at Penalty Pros:
1 - Yes, this will do the trick. Just make sure that you are referencing the non-www version in the disavow. For example "domain:site.com" and NOT "domain:www.site.com". If you want to be super safe, just include the exact subdomains as separate line items.
2 - Google's official word is that you don't need to worry about nofollows, but we've encountered a few situations where nofollow links were pointed out as problematic in failed recon requests. This may be human error on the part of the manual team, but it's probably worth it just disavowing regardless.
Hope this helps and good luck!