but I may have found how to make the image ready for cloning:
rem ### Check If Computer Is Running A 32 Bit or 64 Bit Operating System:
rem ###
http://support.microsoft.com/kb/556009
rem ###
rem ### registry commands must use "/reg:64" switch on 64-bit OS
rem ### this switch is supported in Server 2008 & Win7,
rem ### but a hotfix is necessary for older 64-bit systems:
rem ###
http://support.microsoft.com/kb/948698
set reg64switch=
reg query "HKLM\Hardware\Description\System\CentralProcessor\0" | find "x86"
if errorlevel 1 set reg64switch=/reg:64
rem ### registry location for SEP HardwareID--this is the same on 32- or 64-bit systems
set hwidkey="HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink"
rem ### delete any current SEP hardware identifiers, various possible locations
rem ### ref: How to prepare SEP 12.1 client for cloning:
www.symantec.com/docs/HOWTO54706
for /d %%d in (
"C:\Program Files\Common Files\Symantec Shared\HWID"
"C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\PersistedData"
"C:\ProgramData\Symantec\Symantec Endpoint Protection\PersistedData"
"C:\Windows\Temp"
) do del /f "%%~d\sephwid.xml"
for /d %%d in (
"C:\Documents and Settings\*"
"C:\Users\*"
) do (
del /f "%%~d\Local Settings\Temp\sephwid.xml"
del /f "%%~d\Local Settings\Temp\communicator.dat"
)
reg delete %hwidkey% /v ForceHardwareKey /f %reg64switch%
reg delete %hwidkey% /v HardwareID /f %reg64switch%
reg delete %hwidkey% /v HostGUID /f %reg64switch%
rem ### set HardwareID prefix
rem ### this can be any 20-digit hexadecimal string (using digits 0-9,A-F) in all CAPS
set myprefix=00000000000000000000
rem ### get first MAC address from "getmac" command
for /f "tokens=1" %%a in ('"getmac /nh"') do (
set addr=%%a
goto :endfor
)
:endfor
rem ### if "getmac" fails, try exchanging the line below into the for loop above
rem ### for /f "tokens=12" %%a in ('"ipconfig /all | find "Physical""') do (
rem ### remove hyphens from MAC addr
set addr=%addr:-=%
rem ### for HardwareID, concatenate MAC addr to end of custom prefix
rem ### hwid must be a 32-digit hexadecimal string (using digits 0-9,A-F)
set hwid=%myprefix%%addr%
rem ### Set SEP HardwareID in registry
reg add %hwidkey% /v HardwareID /d %hwid% /f %reg64switch%
rem ### start SEP services
sc start SepMasterService
sc start SmcService