There are several videos available on YouTube, of someone connecting a Win9x/2K/XP machine to the modern Internet, waiting just a few minutes, and then observing (through Process Explorer) the silent introduction of various payloads onto the system.
this is a juicy enough target to justify such a virus.
You occasionally still see probes for Win95/98 era vulnerabilities though, presumably because there are a surprising amount of systems still running those versions and the cost of a probe in case one is accidentally open to the public network. Or as an attacker if you've already got into a private subnet, finding such hosts might be worth it as an extra place to put a reverse tunnel to aid getting back in later if your main route is closed off.