The easiesy way is to disable the Guest account on the Win2k machine, and create a new user account for the person who uses the Win98 machine.
That way, you can assign specific rights to files and folders just for that user.
Oh, you have to be running NTFS for all the security stuff to work properly, so you will need to convert your partitions if they are running in FAT32.