Of course the keylogger could just use the web or mail to export the data. A firewall is virtually useless for stopping outgoung data.
Reallistically it's not worth the time... even code that subverted 50% of the NIT's thats still less systems than code that subverted .001% of the windows boxen out there.