Quack said:
Not without using an install monitor (e.g., Zsoft Uninstaller (freeware)
or Revo Uninstaller (payware)) AND not until after saving a partition
and MBR image backup. First I'd install IsoBuster - with all its crap
foistware (i.e., typical install) - into a VM and then see if this tool
got rid of it all inside the VM. Then, in the real host (not in the
VM), and AFTER the image backup but before installing/using this unknown
software, I'd create a snapshot of the system's state using the
uninstall monitor tool. After the install of this tool, I'd compare the
"before" snapshot with the system's "after" state to record the changes.
Then I'd go look at the log of recorded changes to see if there was
anything obviously suspect or malicious.
There is a lot of malware and rogueware pretending to be useful. Hear
of the AntiVirus 2009 rogueware that hit so many neophyte users? When I
look up the domain registration for freeuninstalltool.com, the
registrant is hiding behind a private registration at GoDaddy. That
means the registrar (GoDaddy) doesn't show the real registrant's info in
the domain registration but instead shows the registrar (GoDaddy). This
is a loop-hole in IANA's requirement that all domain registrations show
the responsible party owning the domain but registrars let their
registrants hide by assuming that responsibility (and charging extra for
that service to the registrants). It lets the registrants hide.
Despite all the excuses, like getting spammed (which is easily avoided
by using a dedicated e-mail account that filters out all e-mails that do
not originate from their registrar), registrants don't hide for a good
reason. That's the first red flag.
A DNS lookup on freeuninstalltool.com returns 76.73.13.182. A
traceroute goes back to and stops at:
tor-proxy.fejk.se [76.73.13.182]
Hmm, maybe that's a TOR node. If so, another red flag. Do you really
want to get anything from an unknown and untrusted site, especially
anything involved with TOR file sharing? ".se" is the ccTLD for Sweden;
however, geolocation lookup on that IP address shows it is around
Chicago, IL USA and is owned by Comcast (an ISP). So some customer of
Comcast is illegally (according to Comcast's TOS) using their home PC as
a server to dole out software from who knows where written by unknown.
Complaints against the site include operating an open or anonymous proxy
(also violates Comcast's TOS). More red flags.
http://www.mywot.com/en/scorecard/freeuninstalltool.com has a poor
rating but
http://www.siteadvisor.com/sites/freeuninstalltool.com has a
good rating (but these ratings are slow to get updated and test them
differently). Personally I wouldn't touch it. Stay away!