Tara,
Thanks for your response. Actually, determined the site was hacked thru the Mail Poet/wysija plug-in. Apparently there is a huge security flaw in versions less than 2.6.7 that can allow hackers to write code into all the php files in the plugin directory
Manually deleted the old plugins & all is back to working. If you have a version of Mail Poet less than 2.6.7 you need to upgrade ASAP.