think... it isn't hard...
Adam, you said it yourself: "Usually, the autoreply also includes a plug for the email scanner software itself."
'Nuff said.
Train your SA's bayesian learner, and/or add a rule that adds a number of points when the word "virus" is found in a mail, and forget about them.