Night- If you mean GrandCrab2, on my system (Win10) everything, including nslookup, was contained at the restricted level.
Also, I just viewed AVG's video (Post #30). You may have noted that some of the samples run didn't work. This normally is indicative of adware/system hack type things. To actually get them to run, there is a setting in File Rating settings- 'Detect potentially unwanted applications". With this unchecked those would just run in containment (not suggesting anyone outside of testing do this!).
Finally, about what started this whole thing- the Spyshelter test running at PL- frankly I have no clue as to how the Comodo developers prioritize files that act in certain ways under Win10, and could care less. The only thing that is of the upmost importance to me is if my system could in any way be changed by malware, and so far I haven't seen it.
I've actually stayed away pretty much from this thread as I don't want to be seen as a Mindless FanGirl, but CF is really, really good.