DNS server changed automatically

No malware. Vulnerability. I believe it is this one: http://forum.mikrotik.com/t/advisory-vulnerability-exploiting-the-winbox-port-solved/118771/1
There were reports from several users claiming same result - changed DNS after unknown admin miraculously “guessed” password and logged in remotely (for example http://forum.mikrotik.com/t/security-attackers-changed-dns-servers/119776/1 )

However, it might be something new… hopefully not. Mikrotik had already too much bad luck this year :frowning: