More than a week
"Some of the anticipated Conficker domains have started to appear on the ASProx botnet over the past week or so."
Actually, for more than 2 weeks. A log with IP changes for all the domains that were anticipated for the 17-31 period shows that the first day some of those domains were pointed to a botnet host was january 20th.
[2009-01-20 12:29:32] The address fmhxqutvccr.org ( ERROR ) was changed to:
24.72.163.104 = h104.163.72.24.cable.srlk.cablerocket.net
24.99.237.81 = c-24-99-237-81.hsd1.ga.comcast.net
24.107.209.119 = 24-107-209-119.dhcp.stls.mo.charter.com
24.165.123.218 = cpe-24-165-123-218.cinci.res.rr.com
24.170.188.201 = user-0calf69.cable.mindspring.com
65.102.56.213 =
67.141.209.213 = h213.209.141.67.dynamic.ip.windstream.net
67.241.202.212 = cpe-67-241-202-212.maine.res.rr.com
68.112.80.134 = 68-112-80-134.dhcp.k717.oh.charter.com
69.66.237.74 = smnr-03-1354.dsl.iowatelecom.net
70.154.82.100 = adsl-070-154-082-100.sip.flo.bellsouth.net
70.244.82.33 = ppp-70-244-82-33.dsl.rcsntx.swbell.net
70.254.126.181 = adsl-70-254-126-181.dsl.hrlntx.swbell.net
76.120.154.98 = c-76-120-154-98.hsd1.pa.comcast.net
98.209.156.151 = c-98-209-156-151.hsd1.mi.comcast.net
The full log is available here: http://nemesis.te-home.net/News/IP_Changes_For_Downadup_Domain_List.html