If they keylogger used the techniques described here

http://www.antionline.com/showthread...hreadid=240901

(Windows rootkits: a stealthy threat)

Then it could remain hidden from any level of inspection. It would not need to run any processes (or it could hide those that did), and it could hide its files and registry entries.