Snow, when we harden Win2K boxes, we usually disable the following;
- Alerter
- Application mgmt
- Clipbook
- Computer Browser (in an AD environment should not be necessary but you can always leave at least one server running this service on your subnet - preferably the DC
- Distributed File System (except for DCs)
- Distributed Link Tracking Client
- Fax Service
- File Replication Service (except for DCs)
- Indexing service
- Internet Connection Sharing
- Messenger
- NetMeeting Remote Desktop Sharing
- Network DDE DSDM
- Print Spooler (if you are not a file/print server)
- Remote Access Connection Manager
- Removable Storage
- RunAs Service
- Smart Card
- Smart Card Helper
- Telephony
- Telnet
- Utility Manager
- Wireless Configuration
Hope this helps
Regards
Terry