If you use K2 2.9.0 or 2.10.0 (dev), then these are just false-positives and you can safely ignore them.
Perhaps ImunifyAV is flagging these files because older releases of elFinder (the media manager widget in K2) had some vulnerabilities. K2 2.9.0+ has updated elFinder files without such vulnerabilities.
Fotis / JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)