Hello Team Spybot,
after you helped me by my last detection rules I decided to build further ones. I tested this keylogger in a virtual machine again and came to this detection rules:

Code:
:: ActualSpySoftware
// {Cat:Keylogger}{Cnt:1}
// {Det:Hancock,2008-07-25}
RegyKey:"<$REG_SETTINGS>",HKEY_CURRENT_USER,"\Software\","ACSPMonitor"
RegyKey:"<$REG_SETTINGS>",HKEY_LOCAL_MACHINE,"\SOFTWARE\","ACSPMonitor"
RegyValue:"<$REG_SETTINGS>",HKEY_LOCAL_MACHINE,"\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List","E:\Programme\ACSPMonitor\ASMonitor.exe"
RegyValue:"<$REG_SETTINGS>",HKEY_LOCAL_MACHINE,"\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List","E:\Programme\ACSPMonitor\ASMonitor.exe"
RegyValue:"<$REG_SETTINGS>",HKEY_LOCAL_MACHINE,"\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List","E:\Programme\ACSPMonitor\ASMonitor.exe"
UninstallByKey:"Actual   Spy_is1","0"
File:"<$FILE_LINK>","<$COMMONPROGRAMS>\ActualSpy\Uninstall Actual Spy.lnk","filesize=637"
File:"<$FILE_LINK>","<$COMMONPROGRAMS>\ActualSpy\Readme.lnk","filesize=1485"
File:"<$FILE_EXE>","<$COMMONPROGRAMS>\ActualSpy\ActualSpy.exe","filesize=44544"
File:"<$FILE_LINK>","<$COMMONPROGRAMS>\ActualSpy\Actual Spy Help.lnk","filesize=1508"
File:"<$FILE_LIBRARY>","<$PROGRAMFILES>\ACSPMonitor\ssleay32.dll","filesize=155648"
File:"<$FILE_EXE>","<$PROGRAMFILES>\ACSPMonitor\settings.exe","filesize=79872"
File:"<$FILE_EXE>","<$PROGRAMFILES>\ACSPMonitor\rights.bat","filesize=60"
File:"<$FILE_TEXT>","<$PROGRAMFILES>\ACSPMonitor\readme.txt","filesize=2034"
File:"<$FILE_TEXT>","<$PROGRAMFILES>\ACSPMonitor\license.txt","filesize=1192"
File:"<$FILE_LIBRARY>","<$PROGRAMFILES>\ACSPMonitor\libeay32.dll","filesize=696320"
File:"<$FILE_LIBRARY>","<$PROGRAMFILES>\ACSPMonitor\hprog.dll","filesize=20480"
File:"<$FILE_LIBRARY>","<$PROGRAMFILES>\ACSPMonitor\hk2.dll","filesize=19456"
File:"<$FILE_LIBRARY>","<$PROGRAMFILES>\ACSPMonitor\hk.dll","filesize=18944"
File:"<$FILE_DATA>","<$PROGRAMFILES>\ACSPMonitor\FILE_ID.DIZ","filesize=386"
File:"<$FILE_EXE>","<$PROGRAMFILES>\ACSPMonitor\f.bat","filesize=67"
File:"<$FILE_EXE>","<$PROGRAMFILES>\ACSPMonitor\asmonitor.exe.manifest","filesize=581"
File:"<$FILE_EXE>","<$PROGRAMFILES>\ACSPMonitor\ASMonitor.exe","filesize=663552"
File:"<$FILE_DATA>","<$PROGRAMFILES>\ACSPMonitor\ActualSpy.chm","filesize=295692"
Directory:"<$DIR_PROG>","<$COMMONPROGRAMS>\ActualSpy"
Directory:"<$DIR_PROG>","<$PROGRAMFILES>\ACSPMonitor"
Directory:"<$DIR_PROG>","<$PROGRAMFILES>\ACSPMonitor\logs"
Maybe you can have a look on it and use it for your next detection update.

regards
N.Jones