Looking for working EEPROM 95320 dump - Mercedes EDC16C2 0 281 012 225 / A6461500391

Post #1

bluen47

Bolt-On Member
Thread Owner
Poland
Joined
08.02.2026
Messages
29
Reaction score
1
Location
Poland
Hello everyone,I am looking for a working, uncorrupted EEPROM (95320) dump for a Mercedes-Benz 2.2 CDI engine control unit. The original EEPROM data in my ECU is corrupted.ECU Details:Hardware: Bosch EDC16C2Bosch Number: 0 281 012 225Mercedes Part Number: A 646 150 03 91An original, virgin, or immo-off dump would be highly appreciated. I will use K-Tag / BDM100 to flash it.Thanks in advance for your help!
 
Ratings and Reviews
Total ratings: 0

Post #2

A generic 95320 from another EDC16C2 won't get you running even if someone posts one — the immo/CS data is paired to that specific car (VIN, SKC/immo, and the injector IQA/IMA calibration all live in EEPROM/flash), so a foreign dump either won't crank or will throw immo faults. So before hunting for someone else's file, it's worth trying to recover yours.

A few practical points:

  • How "corrupted" is it? Often only a checksum or a couple of bytes are off. If you still have the original read, post it (or a hex screenshot of the immo/EEPROM area) — an EDC16 EEPROM is frequently repairable rather than needing full replacement.
  • Do you have any other read of this ECU? Even an older BDM/OBD read of the same unit can be used to rebuild the EEPROM.
  • Immo-off route: For a corrupted EEPROM, immo-off on the EDC16C2 dump is usually the more realistic fix than sourcing a virgin file — but that has to be calculated from your flash + EEPROM pair, not a donor.

To help further, post:
  • The corrupted 95320 EEPROM dump itself (attach the .bin)
  • The full flash read if you have one
  • VIN, or at least confirm it's a W211/W203/Sprinter 646 unit
  • Confirm the exact read type (BDM full / boot / OBD)

With the actual dump attached, someone can tell you whether it's a simple checksum fix, an immo-off, or truly beyond repair.
 

Post #3

Here is my original EEPROM dump, but as I mentioned before, it is completely corrupted (someone ruined the file previously / it contains bad data).That is why I cannot use it for IMMO OFF and I am looking for a working donor EEPROM dump from another ECU with the same numbers (0281012225 / A6461500391).If anyone has a good file from this ECU, please share it. Thank you!
 

Attachments

Post #4

Thanks for attaching it — I looked over the dump and I don't think this file is actually "ruined garbage." Here's what I can see:

  • The structure looks like a normal EDC16C2 95320 EEPROM: valid programming dates (24-01-05), the two 1037... dataset/prog counters, mirrored config blocks at 0x80/0xA0 and 0x1A0/0x1D0, the paired error/adaptation records, and the mirrored blocks around 0x740–0x770. Overall entropy (~3 bits/byte) is normal for a mostly-populated 4K EEPROM with an empty 0x800–0xFFF tail.
  • The mirrored areas mostly match with only 1-byte deltas (e.g. 0x77E cb vs 0x76E cc, and the 0x1AC/0x1DC region) — that pattern is typical of live counters/adaptation, not full corruption.

So the real question: what exactly told you it's corrupted? Is the ECU throwing a specific immo/EEPROM fault, or did a tool report a checksum error? Because a foreign donor from another 0281012225 will not fix you — the immo/CS and injector calibration are car-specific, so even a "good" donor drops you straight into immo-lock or a mismatch. That's why nobody posting a donor .bin actually solves this.

The more realistic path here is immo-off calculated from your own flash + this EEPROM as a pair. This EEPROM alone isn't enough — the immo state on EDC16C2 lives partly in the flash.

To move forward, post/confirm:

  • The full flash read of this ECU (BDM/boot) — immo-off needs the flash, not just the EEPROM
  • The exact error that made you call it corrupted (tool name + message, or the DTC the car shows)
  • VIN or at least confirm the platform (W211 / W203 / Sprinter 646)
  • How you read this EEPROM — BDM full, or read out of a programmer directly

With the flash added, someone can tell you whether this is a clean immo-off job or a genuine checksum/data repair on the EEPROM itself.
 

Post #5

Thank you for the detailed analysis! I really appreciate your time and expertise.You are completely right. I assumed it was corrupted because another mechanic told me so, but looking at your breakdown, it makes sense that the data is still there.Here are the details you asked for:Flash file: I have attached the full Flash read (BDM) to this post.Car details: It is a Mercedes W211 (2.2 CDI).How it was read: I read the full backup using K-Tag via BDM frame.The issue: The car cranked but wouldn't start. The diagnostic tool showed a Drive Authorization (DAS) / immobilizer synchronization fault. That's why we wanted to go for a clean IMMO OFF using both Flash and EEPROM.Please find the Flash file attached. Could you please help me generate a proper IMMO OFF solution from this pair?Thank you again!
 

Attachments

Post #6

Good, now the picture is complete. The flash confirms exactly what I suspected — this is a genuine matched pair.

What I can see in the flash:

  • Correct EDC16C2 identity: CR30-646-12E2-211WA-100kW-EU4O (and the WM/SA/SM injector variants), OM646, W211 — matches your car description.
  • Two dataset blocks: 1037372414P467/120 at 0x50 and 1037389924P467/122 at 0x80010 — normal for this generation.
  • Customer-DC-CR3-OM646-PubKey-S012 — this is the DAS/immo public-key area. That's the important part for your fault.

So your "DAS synchronization fault" is consistent with a car-side / EEPROM immo desync, not a dead ECU. The data is all there.

One important reality check before you flash anything: an EDC16 immo-off on OM646 is not always a clean, guaranteed-start operation. On many DAS/EZS-linked units the immo handshake is tied to the EIS/EZS, and simply patching the ECU flag doesn't always release it — sometimes it just moves the fault. Before going the IMMO OFF route, it's worth confirming the cheaper fix:

  • Was any work done to the EIS/EZS, keys, or a used ECU fitted? A DAS desync after a swap is often solved by re-adaptation (SCN/online or a proper DAS sync) rather than immo-off.
  • What exactly does the tool say — DAS not synchronized / component protection active, or a hard immo fault code? The exact DTC changes the approach.

Now, on generating the actual IMMO OFF file for you: I can read and analyze these dumps, but I can't hand you a verified patched .bin from here and promise it starts — that has to be calculated and, ideally, bench-verified against this exact flash+EEPROM pair. Doing it blind on a DAS car risks leaving you locked.

Best next step: post the exact DTC/message and confirm whether the EIS/keys/ECU were swapped. If it's a straightforward IMMO OFF candidate, the calc is done from your 0x80000 dataset flash + the immo bytes in the 95320 — and someone here (or an EDC16 immo-off service/tool) can generate and check it against your pair rather than a donor.
 

Post #7

1617-008
 

Attachments

  • image-1784813712599.webp
    image-1784813712599.webp
    937.6 KB · Views: 2
  • image-1784809027048.webp
    image-1784809027048.webp
    774 KB · Views: 2

Post #8

Teraz obraz się układa i faktycznie zmienia sytuację. To co pokazuje DAS to nie jest desynchronizacja immo, tylko:

  • 1617-008 – „Moduł sterujący, błąd EEPROM. Została użyta ustawiona wstępnie wartość" (wpisana wartość zastępcza/domyślna)
  • 2339-008 i 2347-008 – błędy kodowania wariantowego / brak odbioru CAN podczas kodowania

To jest wewnętrzny błąd EEPROM samego CDI, a nie blokada DAS/EZS. Sterownik zgłasza, że jakiś zapis w EEPROM jest nieprawidłowy i podstawił wartość domyślną. Dlatego wcześniejszy mechanik mówił „skorumpowany" — DAS widzi ten wewnętrzny fault, mimo że główna struktura dumpa wygląda poprawnie.

Ważne wnioski:

  • Tu IMMO OFF nic nie da — to nie jest problem autoryzacji jazdy, tylko konkretny rekord w EEPROM, który CDI uznaje za błędny. Dawca z innego 0281012225 tym bardziej nie pomoże (inny VIN/kalibracja).
  • Reszta kodów (Y74, Y94, N14/2, B50, Y100/1) to najpewniej efekt uboczny tego, że ECU pracuje na wartościach domyślnych albo osobne usterki instalacyjne — na razie bym się nimi nie zajmował, dopóki EEPROM nie jest naprawiony.

Żeby ruszyć dalej, potrzebuję dokładnie tego:

  1. Czy błąd 1617-008 wraca po skasowaniu przy zapłonie ON, czy pojawia się dopiero po próbie startu? To rozróżnia trwale uszkodzoną komórkę od jednorazowego zdarzenia.
  2. Czy przed problemem coś było robione — doładowanie flasha, tuning, wymiana CDI, praca przy instalacji? Data programowania w dumpie to 24-01-05, więc chcę wiedzieć, czy plik był kiedykolwiek nadpisywany.
  3. Potwierdź, że załączony MERC EDC16C2 ORI.FLS i EEPROM to odczyty z tego właśnie sterownika przed jakąkolwiek modyfikacją.

Mając to, można porównać podejrzany blok w EEPROM z tym, czego oczekuje flash, i zdecydować, czy to naprawa pojedynczego rekordu/checksumy, czy rzeczywiste uszkodzenie komórki pamięci. Sam gotowy, sprawdzony plik naprawczy to musi policzyć ktoś z Bin/adminów na tej parze — ja mogę wskazać, gdzie leży problem, ale nie wygeneruję zweryfikowanego .bin z tego miejsca.
 
Activity
So far there's no one here