As for MAC addresses and Forensics the FBI utilizes, it would not be hard to locate a source of infection or originator of a virus with todays forensic utilities. remember that a MAC address information is available on the WEB and usually is specific to NIC and IP etc...a router or so forth will retain this as well as the TCP packets header... One could easily tear apart a few packets and get what they need.
I believe a MAC header gets stripped out as soon as it leaves the first router. In truth, it wouldn't be very easy to track somebody by their MAC address, it would be fairly difficult, you would have to ask the manufacturer where that card went, and the ISP which customer uses it, and they wouldn't be too eager to give away either of these details. But I'm sure the FBI has enough clout and resources to get any and all info they need from an ISP or computer part manufacturer. And, you could find out who the manufacturer is of a specific card, but pretty much nothing more than that, finding somebody by MAC address wouldn't be so easy.