This may work:
use McAfee Installaton Designer 8.7 and a current copy of framepkg.exe that you obtained from ePO Master repository to produce a custom VirusScan installation package.
(ID 8.7 has an option to embed framepkg.exe as well as any VSE patch, new DAT, etc.)
Edit VirusScan AutoUpdate task schedule in ID so that it updates "when Idle" or "At Logon", etc.
Check the box near the end during ID configuration that says: "Update VirusScan Enterprise at the end of installation".
Use this custom VirusScan install set when preparing your image.
When you install VirusScan onto the image workstation/server, VirusScan will update itself due to the checkbox above and due to the valid sitelist that framepkg.exe has within. If you burn the image later on workstations, standard AutUpdate updates according to the setting above. When MA enforces ePO update task, that one will update.
Do not forget to delete AgentGUID regkey after VirusScan installation as the very last step in image preparation.
NB: Installation Designer must be run on a host that has Virusscan Enterprise 8.7 installed and managed.
This won't work, I'm afraid. It used to work with CMA 3.6, but MA4 and above are MSI packages, as is VSE - and the MSI won't allow two packages to run at the same time, so you can't call an MSI install from inside another.
I think there used to be an article about this but I can't find it at the moment - I'll see if I can track it down.
In your Altiris package you can add a command line execute to force the agent to wake up and check in at the end of the install.
<agent install directory>\cmdagent /p /e /c
We run this to force the agent to wake up and get all its policies immediately after the install of each mcafee product (siteadvisor, HIPS, and AV). Seems to work fine.