Old weakness of D+ that is detected by the AV and cloud. it is pointless to use CIS without its AV and Cloud part. and if you use just CFW you should have an AV running alongside that will anyway detect it.
doing like this video is similar to say "will the airbag of my car will save me from injuries if i dont use the seatbelts"
If the sandbox is set on "Block", the malware cant run. Dont forget that the automatic sandbox is not a virtualized environment (like Sandboxie), it is just based on policy restrictions (and policy restrictions can be bypassed). it is why i run sandboxie (all the time) and Shadow Defender (when i going to load a malicious site or apps).
in addition you can add this on blocked file to block it: *_CRYPT
and protect your file by adding them to Protected Files and Folders (D+ tab) in this method:
*.jpg|
jpeg can be substituted by any extensions but the | sign MUST be put behind it so that sandboxed apps can't modify the extension.