Surely the license to the VLC code is not actually all that relevant; malware suppliers could just as easily offer something that didn't use any VLC code, since their phony VLC doesn't actually have to work all that well, or really at all (since it can't be uninstalled and can do whatever it wants even if the user doesn't intentionally run it a second time).