"Notify Sender", on spam or malicious objects, fails because the sender's email is generally 'spoofed'.
Products already exist which are able to "smart read" the headers of the originating email, and trace these backward to the actual source IP.
(see a program called "abuse" at SourceForge for one example)
It would be excellent if KAV for MS Exchange could apply this same technique.
Thanks