OK, I'm still a little confused. We know the virus was on the computer when it was shut down at the scene and JM says the virus was active between May28th and Jun10th. When forensics did the initial image copy, there was no *advertiser censored* but it was infected w/virus and malware. Then the laptop was activated by defense in 2009, and per Nurmi's claims 1,000's of files were deleted, etc. on that date and it's history showed those *advertiser censored* site links.
If the virus was active in days before and after TA's death, why was there no *advertiser censored* or deletions in the initial image copy?
And if there were links to those *advertiser censored* sites in 2014, wouldn't Nurmi's examiner be able to see the dates of those links and know it was in 2009 if that's when all this occurred?
I also notice that JM is asking for the defense's image copy, is he asking for the image copy for what state it's in now? And will JSS order that be turned over to JM?
And maybe this is something for AZLawyer, but would the attorneys normally make a note of this 2009 incident and virus activity that happened on their watch? Would they have been obligated to advise the PD that this had happened when they powered it up?