Yes, he would have to have jailbroken your phone to install malware. If you see an app called "Cydia", that would indicate conclusively that it was jailbroken. I would recommend restoring the phone as new using iTunes. It is your best shot at removing a jailbreak.
You should also change your network password, your email password and your FB password as well as passwords to anything else you've used from the phone. Put a lock code on the phone.
Your best defense against this sort of thing is to NOT give your phone to people you don't trust.
This is a user-to-user forum, by the way. Apple employees don't participate here. If you want to talk to someone from Apple, make an appointment at the Genius Bar at your local Apple Store.