Those are all in a file called error_log which isn’t part of the default WordPress installation.
You should be fine if you remove the file from /wp-admin/ via FTP or SFTP.
If you want to be doubly sure, carefully follow this guide. When you’re done, you may want to implement some (if not all) of the recommended security measures.
could you please check if any of these are malicious?
http://imgur.com/zCoY6Y4,0GSjqDI,8tBLlEZ,0ESCXps,mJzy0zn
These are the main threats I found.
I am doing all the steps necessary to protect but I don’t want any hidden backlinks or more
No, none of those are, those should be there in the core files.
Exploit Scanner used to ignore unaltered core files like those, but it hasn’t been updated since WordPress 3.5.2, so it doesn’t know how the current core files should be. 🙁