ajax.php, around line 128 to 133 you have this:
PHP Code:
$users = $db->query_read_slave("
SELECT user.userid, user.username FROM " . TABLE_PREFIX . "user
AS user WHERE username LIKE('" . $db->escape_string_like($fragment) . "%')
ORDER BY username
LIMIT 15
");
Modify it to this:
PHP Code:
$users = $db->query_read_slave("
SELECT user.userid, user.username FROM " . TABLE_PREFIX . "user
AS user WHERE username LIKE('%" . $db->escape_string_like($fragment) . "%')
ORDER BY username
LIMIT 15
");