In 1992, NIST published a guide to anti-virus tools that described the state of the art with more candor than you'd get out of a vendor today. Signature scanning was the dominant technique: search an executable file for a known sequence of bytes, flag a match. New viruses turned up every week. A scanner a few months old could miss most of what had been written since it shipped. And depending on how you grouped variants, the same collection of samples counted as roughly 350 viruses or roughly 900.
That spread is the interesting part. Even at the beginning, the list was never one virus, one row. Signatures could use wildcards, so a single pattern might catch a whole family. The relationship between what existed in the wild and what sat in the database was always mediated by somebody's judgment about what counted as the same thing. The model worked anyway, because the discovery rate was survivable: a few hundred known threats, weekly updates, one person able to keep up.
Then the numbers moved. AV-TEST, the independent lab that counts malware samples, documented the curve. In 2000 they received more than 170,000 new samples. By 2007, 5.49 million in a single year. Today they register more than 450,000 new malware and unwanted-application samples per day. Between 2005 and 2007 the aggregate size of product updates went from 520 GB to 1.6 TB, and some vendors moved from shipping definitions weekly to shipping them every half hour.
I was pushing definition updates across a couple hundred university machines while that curve was bending, and the failure you noticed first was never a missed virus. It was the update itself. The download window. The scan that ran long enough that people learned to cancel it. The help desk ticket about a clean file flagged as malware. The upkeep was eating the product.
The industry's response was not to throw out signatures and start over. It was to surround them. IBM built an "immune system for cyberspace" in 1997, meant to derive a detection prescription for an unknown pathogen automatically, in minutes, instead of waiting on a human analyst. Symantec shipped SONAR in 2007, using hundreds of behavioral attributes to identify malware nobody had seen before, though contemporary coverage was clear that it supplemented signatures rather than replacing them. By 2009 Symantec had rewritten SONAR to run proactively and in real time, folding in reputation data: how common is this file, how old is it, who else is running it. A peer-reviewed paper in 2017 still described byte-pattern matching as a prevalent strategy.
So the list survived. What changed was where the confidence lived. When new threats arrive faster than any update cycle can name them, you stop asking whether a file is one of the things you know about and start asking whether it behaves like the kind of thing that does damage. Heuristics, behavioral analysis, reputation scoring, cloud lookup: each one covered a different piece of the distance between what was catalogued and what was actually running on the machine. None of them is as precise as a signature match, and everyone involved knew it. That's the trade you make when enumeration stops being possible.

