It images the OS and user data bit by bit so yes everything is surely backed up.
I really posted it in a hurry, sorry. I just saw "EFI" so I thought geniuses scanned EFI directory and false detected.
Hello, I have just seen this claimed to be in EFI directory https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3aWin32%2fDorv.D!rfn&threatid=2147697472 What bothers me is it can lead to unbootable operating systems just because MS false detected it. Here is the screenshot: