Instead of a fake login page with 2 boxes, a phisher could just create a fake login page with 3 boxes and pass the keycode along with everything else.
The only increased difficulty in phishing, is if the user notes they're seeing a keycode prompt, decides that they probably shouldn't have to enter that again and doesn't just key it in anyway.
When we're talking about people who fall for phishing scams, does that sound all that likely? I mean, these people have a history of ignoring red flags and being blissfully ignorant to what should even raise a red flag.
Now, what two-factor will help mitigate, is casual sniffing, keylogging, shoulder-surfing and saved password cracking.