if this still happens after you 'wiped' the router you maybe weren't thorough enough.
step 1 get the tools:
- download WinBox, NetInstall and the newest RouterOS.
step 2 privacy:
- unplug your pc from all networks, including wlan.
- remove everything from the router, including power cable, usb drive, sd card, etc.
- connect the router and your pc with a normal ethernet cable.
step 3 wiping the system drive:
- follow
https://wiki.mikrotik.com/wiki/Manual:Netinstall and reinstall the newest RouterOS
- if the router doesn't appear even after five minutes, switch to another port on the router, and restart the procedure. some models use port 1 for etherboot, some use port 2.
- make sure you have checked 'Apply default config'. (if unchecked NetInstall keeps the old reset script, you don't want that)
step 4 wiping the BIOS:
- log into the router, default name is 'admin' and empty password.
- if you prefer to configure everything yourself hit Remove, otherwise you can keep the config.
- click on 'System -> Routerboard -> Upgrade -> Yes' and wait a few seconds.
- then restart the router 'System -> Reboot -> Yes'.
step 5 paranoia:
- now is a good time to check the firewall rule again, it might be there again (not problematic at this point), but if it keeps getting created you probably need an entirely new firmware (can't help you there, never done that before), because BIOS is compromised and it spreads into ROS.
- if it doesn't get created again, restart from step 3 to remove the last remnants of the virus.
step 6 security:
- make sure you have set a password for the router 'System -> Password' or 'System -> Users -> Right click on "admin" -> Password...'. this time use a password you have never used before.
- reboot the router again to be on the safe side.
step 7 connect:
- after setting up the basics (bridge, route, ip, dns, etc.) your 'factory fresh' router can now return to his normal place.
i hope this helps cleansing the router.