As far as I can tell, your only option is to get a "real" certificate for your OOB Management Point. Compared to walking to thousands of Computers, this will be really cheap.
Based on my experience you need to walk to some machines anyway when they get stuck in the provisioning process.
I agree that buying a remote config cert will make your life loads easier. However, if that is absolulty not possible check out the sample app in the AMT SDK called usbfile.exe. It will create setup.bin files, and the source code is included. You could probably do something with a batch file like:
prompt user to insert blank thumb
format thumb FAT16
copy to thumb with usbfile
ME prompts user to press Y
Of course your challenge will be that users will need to insert a thumb drive that works (<=2G, single partition) for USB one touch.
So again, I strongly recomend the remote config cert option.
Thumb Drive Info:
Remote Config Cert info: