Falsified IPs makes this problem even more difficult to deal with.

This is the big problem though. The IP's arn't falsified. They are genuine internet connections without being proxied, spoofed, etc. Detecting the movements of trojans is not easy either.

mIRC will issue /server wherever.whatever
rol.vbs will issue /server wherever.whatever
Misc trojan will issue /server wherever.whatever

All look the same visually and from the eyes of a computer.