The only ways i can think of to prove innocence (in general) are a) an alibi b) finding who actually did it.
Both of these don't work here, you can't have an alibi for the whole company for 10 years, obviously. You can't find out who did "it" because there's no concrete example. At the very best you can prove that others did it too.
That said, the trick is pretty vile. Deliberately polluting public malware databases hurts us all.
And, their main development being done in Moscow, do you expect current employees to stick their heads up? There aren't a lot of protections for whistle blowers in Russia. I'm pretty sure they'd be declared traitors, if they did reveal something like this in a formal setting.