DNS server changed automatically

Hard to say. There are several around, and since the noticeable changes in configuration may have happened later than the actual infection, you cannot even say when it happened.

According to the statement of Normis in this thread and some additional details provided elsewhere, an upgrade removes any malware because it removes any files which should not be there. So if the change has happened while you were running 6.40.8 or 6.42.2 and above, it could be a malware exploiting yet undiscovered vulnerability, or some gap in your firewall rules (the malware can also reach the router from the LAN side, so closing access to 'Tik’s management only from WAN interfaces may not be enough). A spontaneous activity of RouterOS is by far the least likely one given that only the DNS setting has changed and to a non-random value.