What is the APPREF-MS file format?
.appref-ms is a ClickOnce Application Reference file used by Microsoft Windows to launch applications deployed with the ClickOnce technology introduced in .NET Framework 2.0 (2004). The file contains a deployment URL pointing to the application's manifest on a web or network server, together with an assembly identity token encoding the application name, version, public key token and processor architecture.
When double-clicked, Windows Shell passes the file to dfshim.dll (the ClickOnce deployment runtime). dfshim.dll contacts the deployment server, checks for available updates, downloads any changed components, and launches the application - without a traditional installer. .appref-ms files are created automatically in %APPDATA%\Microsoft\Windows\Start Menu when a ClickOnce application is installed, acting as the application's Start Menu entry.
Unlike a standard .lnk shortcut, an .appref-ms file stores the original deployment URL rather than a local executable path. This means the launcher always refers back to the server, enabling transparent updates on each run.
The file is encoded as UTF-16 LE text and is typically only a few hundred bytes. It can be opened in Notepad to inspect the deployment URL. ClickOnce and the .appref-ms format remain supported in .NET 6 and later (Windows only) through Microsoft.Deployment.Application.
Security & safety
RISK: MEDIUMAn .appref-ms file itself is safe to receive - it is just a text URL. However, double-clicking it causes Windows to automatically download and execute code from that URL without a traditional download prompt. Social engineering attacks have used malicious .appref-ms files to silently install malware via ClickOnce (CVE-2021-24084 and similar). Never run an .appref-ms from an untrusted source or unexpected email attachment. Inspect the URL inside (open with Notepad) before launching. Microsoft Defender SmartScreen may warn about unknown publishers.
Format details
in a nutshellPrograms that open APPREF-MS files
Technical details
deep spec| Developer | Microsoft Corporation |
| Encoding | UTF-16 LE text (with optional BOM FF FE) |
| Encryption | None in file; ClickOnce validates remote manifest Authenticode signature at launch |
| Container | Plain text - one or two lines |
| Content | ClickOnce deployment URL with assembly identity token (name, version, public key token, architecture) |
| Typical file size | 200 B - 2 KB |
| Launch handler | dfshim.dll (Windows ClickOnce runtime) invoked automatically on double-click |
| Default install location | %APPDATA%\Microsoft\Windows\Start Menu (created automatically on ClickOnce install) |
| Platform | Windows only |
| Technology | ClickOnce deployment - .NET Framework 2.0+ and .NET 6+ (Windows) |
| Update behavior | dfshim.dll contacts deployment server and checks for updates before each launch |
| Manual launch command | rundll32 dfshim.dll,ShOpenVerbApplication <path-to-.appref-ms> |
| Released | 2004 (ClickOnce, .NET Framework 2.0 / Visual Studio 2005) |
| Latest version | N/A - format unchanged; ClickOnce still active in .NET 6+ |
| Specification | docs.microsoft.com |
APPREF-MS conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about APPREF-MS files.