Already, may have missed a step somewhere. I did the first portion of the rule:
ProcessStart.ImageFile = iexplore.exe
And that would be marked as an incident. Well nothing happened. Worked on the 6.0.1 upgrade (which failed, then the next day...everything started working again, odd). Well, now I'm on 6.0.1, and that rule is firing every second. I'm not even sure why it's firing. It's popped about 25000+ times in the past day. I feel like I'm going to get a self DoS. So, I disabled the rule, nothing. Deleted the rule, nothing. It's still firing!!