Good, now the picture is complete. The flash confirms exactly what I suspected — this is a genuine matched pair.
What I can see in the flash:
- Correct EDC16C2 identity: CR30-646-12E2-211WA-100kW-EU4O (and the WM/SA/SM injector variants), OM646, W211 — matches your car description.
- Two dataset blocks: 1037372414P467/120 at 0x50 and 1037389924P467/122 at 0x80010 — normal for this generation.
- Customer-DC-CR3-OM646-PubKey-S012 — this is the DAS/immo public-key area. That's the important part for your fault.
So your "DAS synchronization fault" is consistent with a car-side / EEPROM immo desync, not a dead ECU. The data is all there.
One important reality check before you flash anything: an
EDC16 immo-off on OM646 is not always a clean, guaranteed-start operation. On many DAS/EZS-linked units the immo handshake is tied to the EIS/EZS, and simply patching the ECU flag doesn't always release it — sometimes it just moves the fault. Before going the IMMO OFF route, it's worth confirming the cheaper fix:
- Was any work done to the EIS/EZS, keys, or a used ECU fitted? A DAS desync after a swap is often solved by re-adaptation (SCN/online or a proper DAS sync) rather than immo-off.
- What exactly does the tool say — DAS not synchronized / component protection active, or a hard immo fault code? The exact DTC changes the approach.
Now, on generating the actual IMMO OFF file for you: I can read and analyze these dumps, but I can't hand you a verified patched .bin from here and promise it starts — that has to be calculated and, ideally, bench-verified against this exact flash+EEPROM pair. Doing it blind on a DAS car risks leaving you locked.
Best next step: post the
exact DTC/message and confirm whether the EIS/keys/ECU were swapped. If it's a straightforward IMMO OFF candidate, the calc is done from your 0x80000 dataset flash + the immo bytes in the 95320 — and someone here (or an EDC16 immo-off service/tool) can generate and check it against your pair rather than a donor.