A
Android Central Question
If someone had physical access to the device, when it was new before a pin lock was added, could they root, modify system files with malware, then unroot and those changes stay after a factory reset. I've read that system updates persist after a factory reset, even there's nothing that can be done to remove a genuine system update, so I'm wondering if someone had physical access to the device could system files be modified and those changes persist after any form of device reset. I'm also wondering if anti virus actually checks system files, because presumably there's a lot of diffences between the stock android versions even between different versions of the same device, so does anti virus check system files or just installed apps?