1. Right click on the folder, click properties, click read only. It will ask you if you want just that folder only, or that folder, subfolders, and all files in that folder and subfolders. That would be your choice. If you do set it to read only, that means you can't modify it. If a program uses files in the read only folders, and it needs to modify them, it won't work and cause some errors to happen, so be careful which things you set that to. Operating system files are by default set to read only, but that doesn't stop people from finding ways to hack protected files.
2. Can't say I know of a program, but if you are worried about malicious software, Trend Micro should be scanning files when they are modified. You may want to look more into that. It may be a setting you need to turn on within the software. Contact Trend Micro if you need to know specifically how it works.
3. If you set folders and files to read only, they can't be modified. Except of course if someone deselects read only or if you get a virus that can work around that. Or if you are boot to some sort of pre-install environment like Bart's PE that ignores permissions and file attributes.
4. I'm sure someone has created a live version of XP. However, it is probably not legal.
As far as cloning programs. I prefer Acronis True Image. It is as easy as cloning gets and it is in a nice, user friendly GUI interface.
