I made the same observations as PSIMan.

While using Process Explorer (sysinternals), I could see that IE processes were spawned from this process/service:

C:\Windows\system32\svchost.exe -k DcomLaunch.

Maybe it can help…