You state you have to have this Win2k domain controller in as a helper address, so we can't remove it. You state you don't want to send helper-address to the broadcast address of that server's subnet, which would work around the problem, since a server won't respond with a port-unreachable if the datagram is addressed to the broadcast address. You can't stop the router from forwarding datagrams on port 1604, because you're using that functionality. So, you want to block only return ICMP unreachable responses from the server, but you don't want to use an ACL, which would be the tool for that job.
The sum of it is that you've ruled out all potential ways to address the problem. One of your requirements is probably going to have to bend a little.