Well the CWshredder I assume did get rid of it, which indicates your theory is probably correct (I sound like a Vulcan now). The startup list is listed in Spybot, and theres no information on the one that executes this DLL.
If its any help, spybot's description reads:
Key: HK_CU:RunServices
(If im not mistaken is this running a registry alteration, or is it actually running the services program from the Run prompt?)
Value: Image
Filename: rundll32 C:\WINDOWS\image.dll,install
Currently thinking of a new company name
Sticking to a project idea for once