VBReFormer Desktop Manual
VBReFormer Desktop user manual: install, activate your licence, read the seven views, analyse a binary, export a VB6 project you can reload in the IDE.
Updated on 9/20/202614 chapters
The application installed on your Windows machine. It opens your Visual Basic 5 and 6 executables, reconstructs their source code, and gives you back a project the VB6 IDE can reopen — with the full toolbench: bytes, resources, designer, graphs, cross-references and binary patches.
1. Install
VBReFormer Desktop ships as an MSI installer, one per interface language. The package is self-contained: it embeds everything it needs, there is no framework to install beforehand.
| requirement | |
|---|---|
| System | Windows 10 version 1607 or later, or Windows 11 |
| Architecture | x64 |
| Framework | none — the package is self-contained |
| Connection | required for decompilation and licence validation |
| Interface languages | English, French, Spanish |
Windows XP, Vista, 7 and 8 are not supported. The application relies on a platform that needs Windows 10 at least. If your machine is older, VBReFormer Online works in any browser, on any system — that is the recommended path in that case.
Where the engine works
The application is local; the code reconstruction, however, runs on our servers. That is what the edition's name means — Desktop + Cloud. Everything that is read from the file (the format, the bytes, the disassembly, the resources) is computed on your machine; everything that is reconstructed goes through the service.
The Help ▸ About box tells you at any time the version of the attached engine, the version of the contract, and the list of capabilities served — useful when a feature does not show up: if it is not in that list, it is not the interface that refuses it.
2. Activate your licence
Without a licence, the application opens and works: you can explore a binary, read the disassembly in full, the bytes, the resources and the designer. What the licence unlocks is the reconstruction of the VB6 code and the project export.
One seat at a time
A VBReFormer licence opens one workstation at a time. If you are already using it elsewhere, the application says so clearly and offers two ways out: transfer the licence to this machine from your account, or add a seat.
It is a soft refusal: you have paid, nothing is missing. The message says it that way rather than returning a technical error.
A browser open on VBReFormer Online also counts as a seat: the web studio and the desktop application consume the same licence.
3. The window
- Open a binary. File ▸ Open a VB6 binary (
Ctrl+O). Accepted formats are.exe,.dll,.ocxand.scr. The status bar shows the analysis in progress, then the file name and its compilation form — native code or P-code. - Browse the PROJECT panel. On the left, the binary is presented the way VB6 saw it: forms, classes, modules, and their procedures. The tree fills on demand — expanding a node requests its children; nothing is computed in advance, which keeps opening fast even on a large executable.
- Select a procedure. The views of that node appear on the right. If no view is served for a node, the reason is written on screen rather than an empty panel.
The bottom panels
| tab | what it is for |
|---|---|
| Output | the log of operations. It keeps the language each line was written in, even if you change the interface language — a log is a record, not a display. |
| Diagnostics | what the engine refused to do, and why. The reflex to have as soon as a result surprises you. |
| Analyser | cross-references: callers of a procedure, occurrences of a symbol. The result is clickable. |
Member visibility
Each member of the tree carries its visibility as the binary declares it — (Public), (Private),
(Friend). These are VB6 keywords: they are not translated. A member whose visibility could not be
read carries no mark: we do not write what we do not know.
4. The seven views
They are arranged in three families, and that separation tells you where what you read comes from. It is the most useful thing to understand.
The "Code" family — reconstructed by analysis
| view | what it shows | when to look at it |
|---|---|---|
| Visual Basic 6 | the reconstructed, structured source | by default — this is what you are looking for |
| IR | the intermediate representation | to see what the engine understood |
| Disassembly | the x86 machine instructions | to see what the processor executes |
| P-code | the opcodes of the VB6 virtual machine | P-code binaries only |
Going down this list is going towards the machine. When in doubt about a line: Visual Basic 6 says the intent, Disassembly says the fact.
The "Project files" family — read, not inferred
Designer (.frm), Project (.vbp) and Structure. Nothing here goes through code reconstruction: everything was read from tables in the binary, and what could not be read is written out in plain words rather than filled in. It is the most reliable family of the product, and the one that depends on no inference.
The "Resources" family
See chapter 9.
5. What compilation keeps, and what it throws away
This chapter explains why some parts of your code come back almost intact and others with technical names. The rule is simple:
What Visual Basic needs at run time, it wrote into the file: VBReFormer finds it again. What it no longer needed after compilation, it threw away — and nobody can recover it.
What survives: names of forms, classes and modules · names of controls · event handlers · public members of classes · every interface property · calls to the VB runtime (635 functions) · Win32 API (15,680 signatures) · the structure of the code · the strings.
What is not in the file: comments · names of local variables · names of parameters · named
constants, replaced by their value · names of procedures in .bas modules · the original
indentation · Option Explicit and Enums.
The practical consequence. Your forms come back very readable. Your
.basmodules come back correct, but with technical names (proc_42C506). The Rename function (F2) exists for that, and it propagates the new name to every call site in the project — see chapter 7.
Two verifiable examples
The excerpts below come from SETUP1.EXE, the installation wizard shipped with Visual Basic 6. Microsoft distributes its source code in the same folder — so you can redo the comparison yourself.
A .bas module procedure
Original source, COMMON.BAS:
Sub AddDirSep(strPathName As String)
If Right(Trim(strPathName), Len(gstrSEP_URLDIR)) <> gstrSEP_URLDIR And _
Right(Trim(strPathName), Len(gstrSEP_DIR)) <> gstrSEP_DIR Then
strPathName = RTrim$(strPathName) & gstrSEP_DIR
End If
End Sub
Rendered by VBReFormer:
Public Sub proc_42C506(ByRef arg_8 As String)
If ((Right(Trim(arg_8), Len("/")) <> "/") And (Right(Trim(arg_8), Len("\")) <> "\")) <> 0 Then
arg_8 = (RTrim$(arg_8) & "\")
End If
End Sub
Identical logic, line for line. Right, Trim, Len, RTrim$ are named; the ByRef passing is
correctly inferred. On the other hand the name of the procedure and that of the parameter are lost,
and the constants appear as their value — the compiler replaced them, not VBReFormer.
An event handler
Original source, BEGIN.FRM:
Private Sub cmdExit_Click()
ExitSetup Me, gintRET_EXIT
End Sub
Rendered by VBReFormer:
Private Sub cmdExit_Click()
Set var_18 = Me
basSetup1.proc_41CE2D var_18, var_1C
End Sub
The name of the form, that of the button and that of the handler are intact; Me is recognised;
the called module is named, which tells you where to go. Only the called procedure, which lives in
a .bas, keeps its address name.
The markers
VBReFormer never guesses. A value that cannot be established is marked rather than invented — a plausible and wrong value is the worst result a decompiler can produce.
| marker | meaning | what to do |
|---|---|---|
proc_42C506 |
procedure designated by its address | rename it (F2) |
var_18, arg_8 |
local variable or parameter | read its usage, then rename |
vtbl_3C |
unresolved virtual-table call | the Object Browser often says which library it is |
? |
value not established | look at the Disassembly view at the same place |
A file containing a
?will be rejected by the VB6 IDE. The marker is there for you to decide, not to be recompiled as is.
6. The analysis tools
This is where the desktop edition differs most: it offers a complete workbench, where the web studio concentrates on reading, decompiling and exporting.
| tool | shortcut | what it gives you |
|---|---|---|
| Analyse references | Shift+F12 |
callers of a procedure, occurrences of a symbol — clickable result, and the coverage is quantified: what the analysis does not see is counted, not silenced |
| Symbol list | Ctrl+Shift+S |
the complete inventory, filterable by kind and by scope — it distinguishes read names from synthesised names |
| Call graph | Ctrl+Shift+A |
who calls what, at three scales, with callers / callees filters |
| Control-flow graph | Ctrl+Shift+G |
the shape of a procedure: blocks, loops, back edges, unreachable blocks |
| Object Browser | Ctrl+Shift+B |
"where is this defined?" when the answer is outside the binary |
| API Browser | Ctrl+Shift+P |
prototypes, aliases and notes of the Win32 declarations |
| Cited libraries | Ctrl+K |
what the binary depends on |
| Find VB programs | Ctrl+L |
find the VB executables of a folder |
| Find | Ctrl+Shift+F |
text search across the served views |
| Bookmarks | Ctrl+F2 |
mark places, come back to them (F8 / Shift+F8) |
| Back / forward navigation | Alt+← Alt+→ |
like a browser |
Why the coverage is quantified. The native call graph sees direct calls; it does not see calls through virtual tables nor function pointers. Rather than presenting a partial list as complete, VBReFormer shows what it omits, counted. You then know how far to trust the result.
7. Rename
It is the central gesture of working on a binary: the decompiler gives you back the logic, you give it
back the names. F2 on a symbol, or from the symbol list.
The box shows three things decompilers usually hide:
- the origin of the current name — given by you, inferred by the decompiler, or reconstructed;
- the decompiler's proposals, each with its priority and the source it comes from;
- the original name, which you can always go back to.
Renaming is global. Rename a procedure once, and the call sites in the other modules follow — including those you have not opened yet.
A refused rename is always refused with its reason. Two frequent cases: the engine does not announce the rename capability on this document, or the current view only carries lexical fragments — enough to colour the text, not enough to designate an entity. In both cases the message says so, rather than doing nothing.
8. Bytes and binary patches
Navigate ▸ Show bytes (Ctrl+Shift+H) opens the annotated hex view: it does not only show
bytes, it says what each area represents. Go to address (Ctrl+G) takes you there directly.
Modifying the executable
The "raw" mode lets you write bytes and produce a modified executable. It is framed by four refusals, and each one protects something:
| refusal | why |
|---|---|
| The analysed file is never the destination | the engine never opens it for writing; the interface does not undo that guarantee |
| Overwriting an existing file is confirmed | "this cannot be undone" |
| The Authenticode signature will be removed | your agreement is asked beforehand; you can re-sign with your own certificate |
| A refused patch writes nothing at all | no half-written file |
The web studio does not offer binary patches or the hex view: these are two functions specific to the desktop edition.
9. Resources and designer
The binary's resources
Icons, cursors, bitmaps, string tables, version information: everything a .res file would have
carried. Each entry shows its type, its size and what can be done with it, and extraction is possible
entry by entry or as a whole.
A resource the product does not know how to paint stays listed and is shown as bytes: it is never hidden. And if entries of the directory could not be followed, a warning says so — you then know the list is shorter than what the binary carries.
The form designer
The surface of the form is painted the way VB6 would have shown it, from the properties read in the
binary, in the right painting order. The image of the form can be exported (Ctrl+I).
Properties are read-only: VBReFormer knows how to read the surface of a form, it does not yet know how to rewrite it into the compiled executable. See chapter 13.
10. Export the project
- Check the Diagnostics panel first. It says what could not be done. Reading it before the export saves you from searching later why an element is missing.
- File ▸ Export the VB6 project. Choose an empty destination folder.
- Read the export notes. VBReFormer writes what it could not recover, and why. Some information — external references, compilation options, the startup mode — is in no structure of the binary: it was not erased, it was never there. It is flagged rather than invented.
- Open the
.vbpin Visual Basic 6. The headers the IDE requires (VERSION,Attribute VB_Name) are written. If a reference is missing, add it through Project ▸ References.
Two write refusals that protect you. VB6 files are written in ANSI 1252. VBReFormer refuses to write if that character set is unavailable on the machine — writing in another one would produce a wrong file silently — or if a character of your code does not exist in it, in which case it tells you which one and its code point.
11. The options
| setting | what it does |
|---|---|
| Indentation width | only applies to the reconstructed code: the disassembly, the IR, the P-code, the designer block and the .vbp are not formatted by this editor. |
| Code page (designer) | the page in which the designer's captions and texts are read. A VB6 binary declares its own nowhere — measured on 236 binaries. If the labels of a form show up as inconsistent characters, this is the setting to change. |
Group under With…End With |
off by default. The output is fully qualified (Frame1.Caption), because the compiler dissolves the With blocks and rebuilding them would be a guess. Turn it on if you prefer readability to literalness. |
| Syntax colouring | one role, one colour — the roles come from the engine, which says what each fragment is. #RRGGBB notation; an invalid palette is not applied halfway. |
| Interface language | English, French, Spanish — the change is immediate. |
Rendering settings travel with each display request; they are never set as a session state. Changing the indentation therefore re-analyses nothing.
12. Shortcuts
| shortcut | action |
|---|---|
Ctrl+O |
Open a VB6 binary |
F2 |
Rename the symbol under the cursor |
Shift+F12 |
Analyse references |
Ctrl+Shift+F |
Find in the project |
Ctrl+G |
Go to address |
Ctrl+Shift+H |
Show bytes |
Ctrl+Shift+S |
Symbol list |
Ctrl+Shift+B |
Object Browser |
Ctrl+Shift+P |
API Browser |
Ctrl+Shift+G |
Control-flow graph |
Ctrl+Shift+A |
Call graph |
Ctrl+K |
Cited libraries |
Ctrl+L |
VB programs of a folder |
Ctrl+F2 |
Toggle bookmark |
F8 / Shift+F8 |
Next / previous bookmark |
Ctrl+Shift+F2 |
Bookmark list |
Alt+← / Alt+→ |
Back / forward navigation |
Ctrl+I |
Save the form image |
13. Known limits
Modifying the interface of a compiled executable
VBReFormer reads the surface of a form and all its properties — it does not yet know how to rewrite them into the executable. Replacing an embedded resource and adding a hidden property without recompiling are not available. Binary patches — writing bytes at an address — are (chapter 8).
UserControl .ctx resources
No .ctx file is written at export. If your project contains UserControls with persisted resources,
that part is to be rebuilt.
Windows before 10
Use VBReFormer Online: a browser is enough, whatever the system.
What no decompiler gets past
Comments, names of local variables, named constants: they are not in the file. See chapter 5.
14. Frequently asked questions
A menu function does not respond. Why? Open Help ▸ About and look at the list of capabilities served. If the function is not there, it is not the interface that refuses: the engine does not serve it for this document. The application's messages say so explicitly, too.
Does the exported code recompile as is? Often: on a bench of 149 projects, 121 recompile untouched. The others need a reference added or a few markers dealt with.
The labels of my form are unreadable. That is the code page. A VB6 binary declares nowhere the page of its designer texts — set it in the Options (chapter 11).
Why are my forms more readable than my modules? Because VB6 keeps the names of controls and events in order to work, whereas it resolves module procedures to plain addresses. See chapter 5.
My executable is packed. Is that a problem? Yes: it must be unpacked first, otherwise the VB6 structures are not visible in the file.
Can an .ocx or an ActiveX .dll be decompiled?
Yes, and the inventory of public members is generally richer there, since COM requires naming them.
Is my binary sent anywhere? Reading the format, the bytes, the disassembly and the resources are processed on your machine. The code reconstruction runs on our servers — that is the meaning of the Desktop + Cloud edition.
Is it legal? It depends on your jurisdiction and on your rights over the binary. The intended use is recovering your own code, or code over which you hold the rights or an authorisation.
See also
VBReFormer Online ManualTry without buying