If the users system is compromised there is nothing you can do. Sacrificing general security for that case is silly.
The best defence to a keylogger attack is to have a secondary number vaidation alongside the password that requires you to enter a random subset of that number each time (eg 1st, 2nd, 8th).