If someone has hijacked your computer, they could simply steal your session cookie and do whatever they want regardless of some TOTP secrets or being quick enough. In fact at that point any 2FA becomes meaningless - it's already game over.
Unless of course your bank does some proper, additional verification for large volume transfers.
Of course, that‘s the point: with photoTAN et al. it will request a one-time token for each wire transfer, and the token is based on the information (amount and recipient) of the transfer, which the user needs to confirm on its 2FA device.
Unless of course your bank does some proper, additional verification for large volume transfers.