ASH.DLL is PWSteal.Bankash Trojan. ASH.DLL steals the passwords and bank information. Creates BHO {C6176B04-8896-4446-9939-E00EE94C420F}. ASH.DLL tracks all Intertnet activity. Modifies the value: "Start Page" = "about:blank" in the registry subkeys: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main so that Internet Explorer opens to the "about:blank" page. Modifies the Hosts file to prevent access to several Web sites. Attempts to unregister and then delete the %System%\IEHELPER.DLL file.