Have you ever considered Internet Explorer to be a #lolbin? By navigating to URI: `shell:::{3f6bc534-dfa1-4ab4-ae54-ef25a74e0107}` you can spawn `rstrui.exe` (System Restore). If you modify the `SystemRoot` environment variable and copy over DLLs you can run whatever you like.
I found a signed #lolbin for proxying execution. Use `set` to modify the `SystemRoot` envar to a controlled directory. Plant a binary at path `<controlled directory>\System32\ChangePk.exe` Copy over necessary DLLs. Run `slui.exe`. I'd like to know if it works on your cpu.

