Maybe somebody else can jump in here and offer better advice?
Unless you know exactly what it can do, you should probably run it on an old machine without [direct] internet access.
Cloudburst uses a vulnerability in the virtual-machine display functions of VMware Workstation that can be exploited by a specially crafted video file.
and...
However, the Cloudburst exploit currently has certain limitations: it will only succeed on Workstation 6.5.0 or 6.5.1 or the associated Player versions. In addition, the guest and host must be Windows-based, among other requirements, Immunity said in its release notes.
Assume that if that's been publicly released, more advanced stuff has already been seen in the wild.
But, yeah, paranoia is healthy in this circumstance.
You don't scan it, just use it in a disposable environment (usually a VM, on a non-valuable machine) and see what it does.
ps to answer your other question - antivirus scanners look for patterns in the file itself, so they don't need to install it, but are vulnerable to alternative packaging, modified code, etc etc (of course, scanners also check for problems with installed files, but the first line of defense is to inspect the data - including unpacking zip files etc).
"The reason that PI was not detected is because the attacker embedded a Flash object inside the Excel file. The Flash file was a 0day exploit that could download and execute a file, which in this case was the attacker's PI client."
The Poison Ivy client was downloaded to the target system. Why did the anti-malware software installed there not pick it up? (Attempting to hand-wave this away by talking about 0-day flash exploits really isn't answering the question.)
Looking at the poison ivy website they have a customer portal, so presumably this is how they did it.
There are also methods to pay without leaving a paper trail back to you (pre-paid cards I think).
Edit: It's also possible to modify detectable executables to make them undetectable if you don't want to pay. Virus scanners for the most part work by reading a few bytes from an executable at a particular point, hashing those bytes and if they match a known virus, report it as one. By finding those parts of the executable (there are often multiple signatures, and different vendors will have different signatures too) and modifying them slightly, the resultant hash will be different and the executable undetected.