I made the same observations as PSIMan.
While using Process Explorer (sysinternals), I could see that IE processes were spawned from this process/service:
C:\Windows\system32\svchost.exe -k DcomLaunch.
Maybe it can help…