It is very possible that the obsolete version of Zen Cart you're using on that site has been hacked because of the security vulnerabilities that existed in that version, and that could be the cause of your problems.

As for the SIM module, if it's configured (in your ZC admin settings) to use "offsite" mode, then yes it will send the customer to an auth.net-served page, and will not use a ZC page to request card details.

But instead of adding new ways of collecting payment, your first task should be focused on upgrading the site to a stable version.