.APPREF-MS

APPREF-MS File

Microsoft Application Reference File
Ask a question
QUICK ANSWER

An APPREF-MS file is a ClickOnce Application Reference - a small text pointer Windows uses to launch and auto-update a .NET application from a server URL. Double-clicking it runs the ClickOnce runtime (dfshim.dll), which checks for updates and starts the app. These files appear in the Start Menu after installing a ClickOnce application; open one in Notepad to see the deployment URL inside. Never run an APPREF-MS from an untrusted source - double-clicking it automatically downloads and executes code.

Developer: Microsoft Corporation Category: Settings Files MIME: application/x-ms-application
OPENS ON Windows
Related: .ICA · .DS_STORE · .WMZ · .CFG

On this page

19k+ extensions indexed
Last reviewed Jun 14, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the APPREF-MS file format?

.appref-ms is a ClickOnce Application Reference file used by Microsoft Windows to launch applications deployed with the ClickOnce technology introduced in .NET Framework 2.0 (2004). The file contains a deployment URL pointing to the application's manifest on a web or network server, together with an assembly identity token encoding the application name, version, public key token and processor architecture.

When double-clicked, Windows Shell passes the file to dfshim.dll (the ClickOnce deployment runtime). dfshim.dll contacts the deployment server, checks for available updates, downloads any changed components, and launches the application - without a traditional installer. .appref-ms files are created automatically in %APPDATA%\Microsoft\Windows\Start Menu when a ClickOnce application is installed, acting as the application's Start Menu entry.

Unlike a standard .lnk shortcut, an .appref-ms file stores the original deployment URL rather than a local executable path. This means the launcher always refers back to the server, enabling transparent updates on each run.

The file is encoded as UTF-16 LE text and is typically only a few hundred bytes. It can be opened in Notepad to inspect the deployment URL. ClickOnce and the .appref-ms format remain supported in .NET 6 and later (Windows only) through Microsoft.Deployment.Application.

Security & safety

RISK: MEDIUM

An .appref-ms file itself is safe to receive - it is just a text URL. However, double-clicking it causes Windows to automatically download and execute code from that URL without a traditional download prompt. Social engineering attacks have used malicious .appref-ms files to silently install malware via ClickOnce (CVE-2021-24084 and similar). Never run an .appref-ms from an untrusted source or unexpected email attachment. Inspect the URL inside (open with Notepad) before launching. Microsoft Defender SmartScreen may warn about unknown publishers.

Format details

in a nutshell
FULL NAMEMicrosoft Application Reference Fileaka ClickOnce Application Reference, appref-ms file
DEVELOPERMicrosoft Corporationsince 2004 (ClickOnce, .NET Framework 2.0 / Visual Studio 2005)
MIME TYPEapplication/x-ms-application
TYPEText application-launch reference (UTF-16 LE)

Programs that open APPREF-MS files

Windows3 apps
Microsoft Visual Studio Freemium Use Publish wizard (Build → Publish) to create and manage ClickOnce deployments that generate .appref-ms files.
Microsoft Windows (dfshim.dll / ClickOnce runtime) Built-in Double-click the .appref-ms file; ClickOnce runtime launches automatically via dfshim.dll.
Notepad (view contents) Built-in Right-click → Open with → Notepad to read the deployment URL inside the file.

Technical details

deep spec
DeveloperMicrosoft Corporation
EncodingUTF-16 LE text (with optional BOM FF FE)
EncryptionNone in file; ClickOnce validates remote manifest Authenticode signature at launch
ContainerPlain text - one or two lines
ContentClickOnce deployment URL with assembly identity token (name, version, public key token, architecture)
Typical file size200 B - 2 KB
Launch handlerdfshim.dll (Windows ClickOnce runtime) invoked automatically on double-click
Default install location%APPDATA%\Microsoft\Windows\Start Menu (created automatically on ClickOnce install)
PlatformWindows only
TechnologyClickOnce deployment - .NET Framework 2.0+ and .NET 6+ (Windows)
Update behaviordfshim.dll contacts deployment server and checks for updates before each launch
Manual launch commandrundll32 dfshim.dll,ShOpenVerbApplication <path-to-.appref-ms>
Released2004 (ClickOnce, .NET Framework 2.0 / Visual Studio 2005)
Latest versionN/A - format unchanged; ClickOnce still active in .NET 6+
Specificationdocs.microsoft.com

APPREF-MS conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with APPREF-MS files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about APPREF-MS files.

Frequently asked questions

What is an .appref-ms file?
It is a ClickOnce Application Reference - a small text pointer that Windows uses to launch a .NET ClickOnce application. Double-clicking it connects to the deployment server, checks for updates, and runs the app.
How do I open an .appref-ms file?
Double-click it in Windows Explorer - the ClickOnce runtime handles it automatically. To inspect its content, right-click → Open with → Notepad.
Can I run an .appref-ms on Mac or Linux?
No. ClickOnce is Windows-only. .appref-ms files have no counterpart on other operating systems.
How do I copy a ClickOnce app to another computer?
Copy the .appref-ms file to the other machine's Start Menu or desktop. When launched, ClickOnce re-downloads the app from the deployment URL. The target machine must have the required .NET version.
Is an .appref-ms file safe?
The file format is legitimate, but it auto-executes code from a URL when double-clicked. Only open .appref-ms files from trusted, known sources - malicious versions have been used in phishing attacks.
Why does my .appref-ms say 'application cannot be started'?
Usually the deployment server is offline or the URL has changed, or the required .NET Framework version is missing, or the Authenticode certificate has expired.

References

1Microsoft Docs - ClickOnce security and deploymentdocs.microsoft.com
2Microsoft Docs - ClickOnce application manifestdocs.microsoft.com

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.EXEWindows Executable (Portable Executable)
5.DATProgram Data File (generic)
6.BINCD/DVD Disc Image (BIN/CUE)
7.NOMEDIAAndroid No-Media Marker File
8.MDMarkdown Document
9.RPMSGRestricted Permission Message
10.TMPTemporary File

Related extensions

.ICACitrix Independent Computing Architecture file
.DS_STOREmacOS Finder Desktop Services Store (.DS_Store)
.WMZWindows Media Player Skin
.CFGConfiguration File
.LICLicense File
.CONFConfiguration File

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z