You haven't given us must code to look at so I can only conclude its your SQL statement with the {0} field number.
We cant see what this class is or what it does, but you should check the returned SQL statement to see if its a valid sql statement before running it against the database. The statement above is not unless you are searching for {0} in the name field.
Maybe what you are after is
Select Name from Users Where Name like '%[0-9]%' and name like '%' + textbox.text + '%'