I strongly suspect all the other listed certificates are also marked as revoked but I couldn't be bothered wasting my time checking.
Equifax and Thawte Premium Server CA.
The steps the author takes from that to "this could allow your machine to be compromised" are.... well tenuous at best. The idea that just because a certificate is present, an attacker will easily be able to use that to sign malware and bypass anti-malware protections as a result doesn't appear supported by the evidence presented.
I'm all for pushing O.S and Browser vendors to remove many of the trusted certs in the root store...but this is just silly and frustrating.
Articles like this make the security industry lose credibility.
Equifax is only a 1024-bit RSA key, which isn't ideal, but it expires on Aug 22nd this year and the key-size of the root doesn't impact confidentiality.