I think it doesn't work.
Because the registry key is also hacked in the global area (HKLM) Local Machine RegKey.
When the system is restarting, it will be running the hacked programs.
Maybe you can think about the Virtual Machine to isolate the running space and the viruses.