But is it possible for it to get out, and attack my actual system?
Occasionally on actual system startup, I get a Norton AV warning message saying something about a possible virus trying to disable it... I'm not worried much yet... All I would have to do is just delete my VMC
However, you still have to be careful when copying files over or sharing external devices like flash drives, as since they are accessible by both the virtual machine and the normal machine the spyware could spread from one to the other.