Windows defender deve aver rilevato solo la pagina di phishing, in genere quelle pagine non vanno a modificare il sistema operativo o i programmi, ma ti vogliono solo rubare la password.
Hai provato un riavvio di thunderbird senza componenti aggiuntivi o a fare un nuovo profilo di posta?
As its name suggests, malware identified as Trojan.HTML.Phishing.[variant] will try to perform a phishing attack, which involves luring the user into giving away their personal or financial details by impersonating a legitimate entity.
Phishing attacks typically involve communications (either email messages or a web page or site) that are specially crafted to look similar or even identical to the correspondence or portal of a legitimate company, so that the user is deceived into trusting it.
Fraudulent web pages or sites often provide a form, where the user is lured to submit their login, personal or financial details. Any information unwittingly submitted by the user through it is compromised.