While following the above Advise with Autoruns, I would strongly suggest just to disable suspicious items, not delete them.
also if in doubt, please save the program log as autoruns.arn , rename to Autoruns.txt & attach here.
from the routine of periodically terminating cmd & regedit , I would guess this is the action of a trojan infection or some variant of Brontok or a similar worm, you can recover from using the below link
Microsoft Malicious Software removal tool
finally if Malwarebytes as already suggested did not do the trick, please post a hijack this log.





by: scwoaPosted on 2009-04-16 at 22:24:00ID: 24165076
Get autoruns from sysinternals (microsoft) and see what is running at startup. http://technet.microsoft.c om/en-us/s ysinternal s/ bb963902 .aspx
A lot of the un-signed items are suspicious, but not all. Delete entries that look suspicous. This is a judgement call...
Get malwarebytes and run it, if you haven't already. www.malwarebytes.com
Check for more than one copy of cmd.exe on the drive, and also the shortcut, also check the permissions on the file, see if they changed.
Check in c:\windows & c:\windows\system32 and look for files that changed in the last week. Then google them and see if they are spyware.
Find an original XP SP 2 Disk, and copy in cmd.exe and regedit, then mark them as read-only.
Or just give up and format and reinstall. :)