Everybody is seeing a rise in port 5000 probes. These are not caused by the (very old) Sockets de Troie trojan.

It's probably caused by 2 new worms; Bobax and Kibuv.

Bobax uses a probe on port 5000 to identify windows XP and Kibuv tries to exploit the very first vulnerability found on XP (UPnP bug).

Bobax:
http://vil.nai.com/vil/content/v_125304.htm
http://www.sophos.com/virusinfo/analyses/w32bobaxa.html

Kibuv:
http://vil.nai.com/vil/content/v_125306.htm