i found this reference from a malware that use ctfmon.exe to hide itself. take a look:
http://www.sophos.com/virusinfo/analyses/w32hobota.html