Hi,
I'm very sorry to hear about your issues. This is, most likely, not the case of functions.php but the third party script for cropping images called TimThumb. In November of 2011, people have discovered the vulnerability in this script and a lot of sites using it were hacked. We have released patched themes and plugins to fix this vulnerability, but your membership has expired half year before that. Because of that I'm assuming that the vulnerable script is still part of your site, and that's how the hackers were able to hack it and add their code to the functions.php file in order to make sure it gets executed asap.
I'm attaching a zip package to this post with the files that should be placed in your themes' root directory. The timthumb.php file should be replaced with the new one from phpThumb, with old file name to maintain compatibility. We once again would like to sincerely apologize for your trouble.
This attachment is hidden for guests. Please log in or register to see it.
Thanks,
Jakub