Yea, I know, there are a LOT of posts about the trojans lurking on port 5000. Now I have a problem with it. I have XP, and by default, plug and play is enabled. Now, sometimes I will encounter strange behavior, ex: my cable connection suddenly going dead...I routinely run netstat -an thru DOS, and what do you know, an IP is connected to me via port 5000. Now, I dont know if it actually is a trojan, being it is the same IP every time.I have Norton AV and Agnitum Outpost, and my system is clean. Ive ran The Cleaner likewise. Is it a Microsoft service connecting to me? Or is it a ....gulp.....trojan.