Hello,
In this case, you may want to get a USB drive that is around 16 GB and then use Rufus or Ventoy to be able to boot a live instance of Linux (I recommend Ubuntu or Linux Mint). This way, you aren't booting from the infected Windows. Then, you may plug in a separate storage device (e.g. SSD, flash drive, etc.) to move the files from the Windows installation from the live Linux environment. This way, you can fetch logs without having to boot from Windows.
On Windows, the logs are located at C:\Windows\System32\winevt\Logs. However, from a Linux environment, you will first have to mount the Windows disk. On many distributions, you may do this by opening the "Disks" app and then selecting the Windows partition, then selecting "Mount". Do the same thing with the external drive (if necessary). After you have done so, go back to the Windows disk. You should see a link where it says "Contents: NTFS — Mounted at" and a link next to its mount point. Select that link, and it should go straight to the root of the Windows drive. You may repeat these steps with the external drive as well, if needed.
Navigate to Windows/System32/winevt/Logs and then copy the event logs and any other files you may need onto the external drive. I would recommend moving files one-by-one (or in chunks of files) so that you don't accidentally transfer the virus back.
You may proceed to wipe the client's PC and move the files back.
If you have any questions or need clarification, please let me know!
I hope to hear back from you.