Do you see any Splunk process running ? Do you see any splunk process holding any files/IO open?
Have you rebooted the system since the uninstall? Do you still see connection from the old heavy forwarder to the indexers?
Are there other heavy forwarders the data could be coming from?
If the inputs.conf has the wrong hostname, the events will appear to be from a different host. This can happen when images are cloned.
The same is true for the GUID, if you are seeing license usage ensure there isn't another host using the same GUID.