Because, sometimes I'm not perfect I'll just send my funds out to the address without crosschecking like everyone else who has something to attend immediately.
It takes 10 seconds to double check an entire address. Even if you are in a rush for your transaction to be confirmed, the chances of a block being found in those few seconds are low, and even if it was, your transaction probably wouldn't have spread through the network and in to relevant mempools and candidate blocks fast enough to make a difference. Your transaction will almost certainly be confirmed at the exact same time whether or not you double check the address, so there is no excuse for not doing it.
You can keep your OS updated, download every piece of antivirus software there is, and all the rest of it, and still fall victim to this malware. The only 100% protection is to accurately double check the address against the source after you have copy and pasted it. It takes 10 seconds. Just do it.
Checking the first 5-7 characters at the beginning and / or end of the address should be more than sufficient. The addresses that clipboard malware sneak in usually look nothing like the intended address since they'd have to generate a vanity address on the fly which isn't really feasible.
There are definitely some pieces of malware out there which pick addresses from a pre-generated database which have matching characters at the start and/or end to trip up people who only check a few characters. As time goes on and technology continues to develop, this problem will only get worse. If you are going to check 5 characters at the start and the end anyway, it is absolutely trivial to just check the whole address.