Hm. the sandboxie piece above is a good, good start (not bulletproof, has some flaws that can be exploited to identify a location eventually) but a good, good start.
I work as the senior net admin for a large global company and I can tell you that Tor is easier to sniff out than you think, so unless you've got encryption running alongside, and also spoofing, (and have staged a good network for your incursion),... then a really good net admin could leverage certain resources to find you...
BUT... to be honest, none of this discussion has any immediate 'threat relevance' to someone, UNLESS it is actually the fibees or interpol or another fed agency at the national level that has power of subpoena over ISPs, because (having been on the tracker end of several investigations myself), I can tell everyone here first hand just how slow and laborious it is to really 'pinpoint' someone's actual physical location. (I hopethis type of talk is permitted and the mods will alow it,... if not please warn me and I will never do it again

). The truth is that local law enforcement at the state level (and below) in the US almost NEVER has the authority or the resources to execute a state-level attorney general subpoena of ISP records (and even if they can twist some public official's arm into it, it takes them forever), which means that (typically) the closest trace someone ever gets is the NOC center or DSLAM station closest to a perpetrator,... which still leaves thousands of IPs to check and sometimes hundreds of square miles in question,... unless they get that subpeona. Even computrace (famous computer 'Lo Jack" company that everyone's heard of yea?) will tell you that it takes time to track someone, and they have ESTABLISHED partnerships with most ISPs.
On top of that, most people think that ISPs have a magic button that can tell their net admins something like [IP address assigned = physical address location], just like that, with the push of a button. That is not true. In fact, some ISPs can't even guarantee to have log files beyond 10 days for IP leases, even for law enforcement availability.
That's why, if someone was really were going to do something unorthodox (or nefarious) then I would principally have to agree with 'ultimatium1''s short, but accurate post above.
Real 'hit and run' scammers enter a network using removable WiFi cards capable of promiscuous mode settings and re-assign different MAC addresses each time they used (sometimes scrolling, after disconnecting, then reconnecting in the same place several times), then they just crack WEP at your nearest McDonalds (I won't get into that side of it) or worse yet, wardrive an unsuspecting little old lady in your neighborhood, surfing via SSL/VPN (and maybe even surfing a network of proxies on top of it, not that by itself it will help, but it will confuse the issue for law enforcement,... again extending the TIME it takes to investigate).
A setup like this allows a perp to do their business for about an hour, no browser interaction in most cases, just remote cmd line - but if there is it is a stripped down browser that caches nothing and does not execute JS or store cookies. Disconnect, and then leave.
The timeline for tracking something like this is typically weeks if not months. And as soon as the public IP at McDonalds (or wherever the staging area was) is known, then the only prayer law enforcement might have is that a video camera caught a license plate or something, because at this point the person is long gone. Usually, at that point it is a matter of dollars. If the perp committed a serious crime and there is over 20K of theft involved, they might continue to pray for a hail mary and pursue it with 'on the ground' tactics like interviewing people and expanding the searchable area for subpeonaing video camera footage, but this will most likely prove futile.
If the crime was low grade or just mischief, typically the case just gets recorded (along with MAC/IP/VPN endpoint info if they can get it, etc.). Not worth the continued waste of resources and public $ to pursue.
I have gone through 3 of these types of situations, and trust me. They are long, they are boring, and (if the perp simply at LEAST chose a public WiFi network to stage his/her incursion), then it ends in frustration and in eventual concession that not much can be done.
Most people that do nefarious things online get caught because they leave a PAPER TRAIL LATER ON of either money they scammed, or the ill gotten goods they attempted to get,... and it is that paper trail that catches up with them.
We had a situation last year where we ended catching someone who pulled off the job perfectly,... except he then pawned something he ordered online with scammed money, and the pawn people recorded it as matching something suspicious in their database that we had reported to the pawn network here in this state,... and bam. 48 hours later, person was caught and in jail.
Here's the real moral. Place nice on line.

Even the best of the best have nothing if they don't have a bulletproof exit strategy.
Anyway, that's my long-winded 2 cents.
Cheers.
