as the antivirus now is in 3.0 right? (why is the antivirus by itself in 2.0

)
The antivirus is version 3 now, it's no longer 2.0. That's the old verion, we usually refer to it as 2.0 beta because it was beta and never stopped being beta. :-)
I believe it's been a while since Matousec tested CFP, since they want Comodo to pay for every test. They won't do that for every new version (which usually addresses previously discovered leak vulnerabilities). The firewall of CIS (just uncheck the AV on installtion to get the FW only) is newer than the standalone CFP.