This question has been answered by muzzargh. See the first response.


This may or may not be relevant.
Have you checked the permissions for the Admin user account ?
In Evo you can't modify the account settings for the main Admin / super user account. But it can be modified via phpMyAdmin.
A suggestion:
Using phpMyAdmin look at the DB table "?_user_roles" where "?" is your table prefix.
You will see all of the user accounts and you should have something like "edit / copy / delete" and a load of table headers.
For the main admin account, all of the elements should have a "1" in them - if that's not the case and there is a "0", click edit, find the culprit and change it from "0" to "1" - save and log back into the manager, clear Evo cache and try modifying the user again.
If it works great, if not, go back to the DB and check again - if the settings have been changed again to "0" the site probably has hacked code somewhere.
Background:
One of my sites was hacked some time back and after upgrading, deleting all suspicious code and removing all modified files, the site was hacked again within 12 hours.
The hacker had injected code in the DB and modified the Admin user account - each time I modified the user the malicious code changed the settings again.
I couldn't find the code that kept doing the changes so my end-solution was a complete re-build which ensured that no dodgy code or files were still there.