Mg1 vin change helpp

Post #1

Eltunbimer

Stock Member
Thread Owner
Georgia
Joined
13.08.2026
Messages
8
Reaction score
1
Location
Georgia
I need help changing the VIN on an MDG1. Could someone please help me with this? Thanks in advance!

New vin:3MW5U7J07M8B53372
 

Attachments

Ratings and Reviews
Total ratings: 0

Post #2

From the dump you attached, this is a genuine MG1CS201 INT EEPROM (768 KB, TC298TP, B38/B48/B58/N63 family), and I can see the current identity inside it:

  • VIN in file: WBADZ2C0XLCE05137
  • HW/SW string: "10SW051332P
  • Chassis short: CE05137
  • Type code: LBMXJ03.0B07
  • Target new VIN: 3MW5U7J07M8B53372 (17 chars, valid format — 3MW = BMW Mexico)

A few important points before you touch this file:

1. Plain hex-replace will not work cleanly on MG1CS201 INT EEPROM.
The VIN and its short form (last 7) are stored in several regions, and the surrounding blocks are protected by CRC/signatures (you can see the "BEEFxx" record markers and the 0xA5 headers at 0x0 and 0x60000 — those are structured records, not free space). If you only overwrite the ASCII VIN, the ECU will usually either revert on next KL15, throw internal faults, or refuse to sync with FEM/CAS.

2. You need a tool that understands the MG1 EEPROM layout, recalculates the affected CRCs and updates all VIN copies + the 7-digit short VIN. Doing it by hand in a hex editor on this generation is not recommended.

3. Immobilizer / pairing
Changing the VIN in the DME does not by itself pair it to another car. On F/G-series with MG1 you still need:
  • correct ISN in the DME matching the target FEM/BDC (or CAS on older),
  • FEM/BDC coded to the new DME,
  • after flashing, VIN write via UDS and a proper vehicle order alignment in ISTA/E-Sys.

To give you a precise next step, please confirm:

  • Which tool/hardware do you have for this DME? (PCMflash, bFlash, MagicMotorsport Flex, CGDI/Yanhua/Autohex, MDG1 OBD, etc.)
  • Is this a donor swap into a running car, or a clone of another DME to this one?
  • Do you also have the full external flash read of this DME, or only the INT EEPROM you posted? The VIN also lives in the external flash data area — INT EEPROM alone is usually not enough.
  • Do you have the ISN of the target car (VIN 3MW5U7J07M8B53372) and access to its FEM/BDC?

Once I know the tool and whether you have the EXT flash too, I can point you at the correct workflow for that specific chain.
 

Post #3

don’t need to change the ISN. I just need to change the VIN temporarily to check something. After checking it, I will write the original EEPROM back.
 

Post #4

Understood — for a temporary check that's a lot simpler, but a couple of practical notes:

Easiest route: don't touch the EEPROM at all.
On MG1 the VIN can normally be written over the bus with a UDS job (Tool32 / ISTA / E-Sys, e.g. the VIN write / VIN_SCHREIBEN type job on the DME). If your test only needs the DME to report a different VIN, that's reversible in seconds and there's no CRC or write-cycle risk on the internal EEPROM. I'd try that first.

If you still want to do it in the EEPROM file:
  • In your dump the identity exists in more than one form — the full ASCII WBADZ2C0XLCE05137 and the 7-digit short VIN CE05137. Both have to be changed consistently, otherwise the DME can throw internal plausibility faults. For your target that means 3MW5U7J07M8B53372 and 8B53372.
  • The file is a structured record area (0xA5 headers at 0x0 and 0x60000, "BEEFxx" record markers), so depending on where each copy sits there may be a block checksum over it. A plain hex overwrite may be accepted, or may be rejected/reverted on the next KL15 cycle — that depends on the block. I can't confirm from a sampled read which of the copies are checksum-covered.
  • Keep the original 768 KB read untouched as your restore file, and verify after writing by reading back and comparing.

Also be aware the DME will likely log DTCs for VIN mismatch against FEM/BDC while the test VIN is in there — normal, clear them after you restore.

To point you at the exact method: which tool are you using to read/write the INT EEPROM on this MG1CS201 (bench/boot with Flex, AutoTuner, PCMflash, CG FC200...), and does that tool have a built-in VIN-change function for MG1? If it does, use its VIN function rather than a hex editor — it handles the copies and any checksum for you.
 

Post #5

When I try to write the VIN using E-Sys, I get this error.
IMG_6709.webp
 

Post #6

Hata mesajını göremiyorum — gönderdiğin mesajda ekran görüntüsü/metin gelmemiş. Tam hata satırını (E-Sys log penceresindeki kırmızı satır dahil) ekler misin?

Bu arada birkaç önemli nokta, çoğu durumda sorun buradan çıkıyor:

1. E-Sys'te "VIN yazma" diye doğrudan bir DME fonksiyonu yok.
E-Sys'te VIN, araç siparişi (FA/VO) üzerinden ve genelde CAS/FEM/BDC tarafına yazılır. DME'ye (MG1CS201) VIN yazmak istiyorsan doğru yol Tool32 ile ilgili SGBD'yi açıp VIN yazma job'unu çalıştırmak (ör. STEUERN_FGNR_SCHREIBEN / FGNR_SCHREIBEN tipi job, SGBD sürümüne göre isim değişir) ya da ISTA üzerinden servis fonksiyonu. E-Sys'i zorlamak yerine bunu denemeni öneririm.

2. MG1'de VIN yazımı security access ister.
DME kilitliyse veya seed/key seviyesi tool tarafından karşılanmıyorsa "negative response / 0x33 securityAccessDenied" ya da "conditions not correct (0x22)" alırsın. Bu, dosyayla değil oturumla ilgili bir hata.

3. Sık görülen E-Sys hataları ve sebepleri:
  • "No CAFD for SWE" / boş coding blokları → hedef (Target) yanlış veya PSdZData aracın I-Level'ından eski
  • FA yazımı reddediliyor → VO/FA formatı araca uymuyor veya VCM'e yazma adımı atlanmış
  • Token/FDL hatası → Launcher tokenı yüklü değil

Sana net cevap verebilmem için şunları yaz:
  • Hatanın tam metni veya ekran görüntüsü
  • E-Sys sürümü + kullandığın Launcher (PRO/Plus, token var mı)
  • PSdZData sürümü ve seçtiğin Target (F020, S15A vb.)
  • Araç: şasi ailesi ve model yılı (dosyadaki VIN'e göre F/G serisi B48/B58 gibi görünüyor, teyit eder misin)
  • Bağlantı: ENET kablo mu, hangi arayüz
  • VIN'i tam olarak nereye yazmaya çalışıyorsun: DME'ye mi, FEM/BDC'ye mi, yoksa FA/VO yazımı mı

Bu bilgilerle hatanın E-Sys tarafı mı yoksa DME'nin reddi mi olduğunu ayırt edebiliriz.
 

Post #8

Now the screenshot came through — thanks, that helps a lot.

What the log actually says:

Code:
--> WriteDataByIdentifierVIN
<-- Error: SWT diagnosis for ECU "[BaseVariant=DME_BAC2, DiagAddress=12]" failed! [C057]
-MessageID is used multiple times, so MessageText may be ambiguous-the result contains an error [370]

Two separate things in there:

  • The [370] line is cosmetic. It's an ODX/PSdZData message-table warning ("MessageID used multiple times"), it is not the reason the job failed.
  • [C057] "SWT diagnosis for ECU ... failed" is the real error. E-Sys sent the UDS write (0x2E to DID F190) to the DME at DiagAddress 0x12 and the ECU answered with a negative response. E-Sys just doesn't show you the NRC in this window.

Most likely cause on MG1 (general BMW behaviour, not something I can confirm from your dump alone): VIN in the DME is effectively write-once. If a VIN is already stored — and in your file it is, WBADZ2C0XLCE05137 — the ECU will refuse 0x2E F190 with 0x22 (conditionsNotCorrect) or 0x31 (requestOutOfRange). It only accepts a VIN write when the field is virgin/blank, which is why the normal workflow is: reset/virginize the DME on bench, then write VIN over the bus. That fits exactly with what you're seeing, and it also means E-Sys is not going to give you the "temporary VIN" trick you were hoping for.

Quick tests before anything else:

  • Run ReadDataByIdentifierVIN from the same list. If it returns the VIN, comms/session are fine and the problem is purely a write permission/precondition — not your setup.
  • Terminal 15 ON, engine off, stable supply, no ISTA/other session open in parallel.
  • Open the E-Sys trace log (...\EC-Apps\ESG\logs\ or your configured log folder) and find the line for that job — it contains the raw response (e.g. 7F 2E 22 / 7F 2E 31 / 7F 2E 33). That NRC tells us definitively whether it's "already written", "security access denied" or "wrong session".

If the NRC turns out to be securityAccessDenied (0x33), the write path is fine but E-Sys isn't unlocking the DME — then Tool32 with the matching SGBD, or ISTA's service function, is the better route.

Post the raw NRC from the trace log plus your E-Sys version and PSdZData version, and I can tell you which of the three cases you're in.
 

Post #9

How can I change the VIN using Tool32? Is there any risk? The car is a 2019 G14 with a B58 engine.
 

Post #10

Tool32 is basically just a front-end for the same UDS jobs E-Sys uses, so it will hit the same ECU precondition wall — but it's more transparent about the negative response, which is what you want for diagnosis. Here's the practical path for a G14 B58 (MG1CS003, not CS201 by the way — CS003 is the petrol B58 variant on G-series):

Setup
  • Open Tool32 (part of your E-Sys / EDIABAS install, usually C:\EDIABAS\Bin\Tool32.exe).
  • File → Load SGBD → pick the DME SGBD. For a 2019 G14 B58 that's normally GMOTOR (the generic G-series engine SGBD, it auto-detects the actual DME variant). If it fails to answer, try the specific one, e.g. MGUMOT or the direct variant name.
  • Check EDIABAS.INI is set to your ENET interface (Interface = ENET, RemoteHost = 169.254.…), otherwise you'll get IFH-0009.

Read VIN first (safe, no writes)
  • Job: STATUSLESENFGNRLANG (or STATUSFGNR depending on SGBD version). Press F5 / Execute.
  • If it returns your current VIN cleanly, comms and security level for reading are fine.

Write VIN
  • Job name varies by SGBD version, look for one of: STEUERNFGNRSCHREIBEN, FGNRSCHREIBEN, SCHREIBENFG_NR.
  • Argument: the 17-char VIN as a string, exactly as the job help pane describes (some want "FGNR;3MW5U7J07M8B53372", some want just the VIN — the help window on the right side of Tool32 tells you the exact format for that SGBD).
  • Execute. Look at the JOB_STATUS / result lines.

What you'll probably see, and what it means
  • JOB_STATUS = OKAY and VIN updated → done.
  • NR 22 (conditionsNotCorrect) → DME already has a VIN stored and refuses to overwrite. This is the normal MG1 behaviour and matches your E-Sys failure. Tool32 will not bypass this — the ECU itself is refusing.
  • NR 33 (securityAccessDenied) → job didn't run SecurityAccess first. Some SGBDs have a separate SECURITY_ACCESS / FREISCHALTEN job you have to execute before the write. On MG1 the seed/key exchange is handled internally by the SGBD if your EDIABAS is a proper BMW build.
  • NR 31 (requestOutOfRange) → format of the VIN string is wrong for that job.

Risk assessment
  • Low risk to try, because the DME will simply refuse with a negative response if it doesn't like the request — nothing gets half-written. UDS 0x2E is atomic.
  • Real risk is if the write does succeed: then the DME's stored VIN no longer matches FEM/BDC, DSC, EGS, KOMBI, HU, etc. You'll get a wave of VIN-mismatch DTCs across the whole car and possibly comfort/CBS features acting up until you either restore the VIN or write the original EEPROM back. Engine start itself is not gated by VIN (it's gated by ISN ↔ FEM), so the car will still crank and run.
  • No CRC / no flash risk — this is a UDS data write, not a flash operation. It doesn't touch calibration or checksums. Your original 768 KB EEPROM read is still your safety net.

Honest expectation: on a 2019 G14 with the original DME that already has WBADZ2C0XLCE05137 burned in, Tool32 will almost certainly answer NR 22 as well. The clean way to get a fresh VIN into an MG1 is to virginize the DME on bench first (MG1 clone/virgin operation via a bench tool like Bitbox / PCMflash / MagicMotorSport / Autotuner with the right MG1CS003 protocol), then WriteVIN over the bus accepts it.

If you can, post the exact NR code Tool32 returns — from there we'll know for sure whether it's precondition, security, or format.
 

Post #13

MG1'i "sıfırlamak" (virginize etmek) tek tıkla yapılan bir işlem değil, ne yapmak istediğine göre farklı seviyeleri var. Kısaca ayıralım:

1. Sadece adaptasyonları sıfırlamak
ISTA → Servis Fonksiyonları → "Adaptasyon değerlerini sıfırla" ya da Tool32'de STEUERNRESETADAPTIONEN benzeri job. Bu VIN'i, ISN'i, immoyu hiç etkilemez. Sadece öğrenilmiş değerleri temizler. Risk yok.

2. DME'yi "virgin" hale getirmek (VIN + ISN + immo eşleşmesini silmek)
Senin asıl aradığın bu — çünkü VIN yazımının reddedilme sebebi DME'nin zaten evli olması. Bunu bus üzerinden BMW tool'larıyla yapamazsın; MG1'de bu iş bench modunda, DME'yi söküp doğrudan bootloader üzerinden yapılıyor. Kullanılan tool'lar tipik olarak:

  • PCMflash (modül 71 – MG1/MD1 bench)
  • Bitbox / BFlash MG1 bench protokolü
  • Magic Motorsport Flex, Autotuner, CMD, New Genius vb. MG1CS003 bench desteği olan tool'lar
  • Bazılarında ayrı "clear ISN / virginize" fonksiyonu var, bazılarında INT + EXT flash'ı okuyup manuel olarak temiz bir eşe yazman gerekiyor

Bench bağlantısı: DME'yi çıkarıyorsun, bench kablosuyla besleme + CAN + boot pini veriyorsun, tool MG1CS003 profilinde full backup alıyor (INT flash + EXT flash + EEPROM). Sonra "virginize / clear ISN & VIN" fonksiyonunu çalıştırıyorsun. Bundan sonra araçta VIN yazımı 0x2E F190 ile normal kabul edilir.

3. Riskler — dürüst olmak gerekirse ciddi

  • MG1'de yanlış tool profili veya yarım kalan yazma = brick. Bu ECU'da recovery her tool'da yok.
  • Virginize sonrası CAS/FEM/BDC ile ISN eşleşmesi bozulur. Aracın çalışması için sonra yeni ISN'i FEM'e senkronize etmen veya orijinal ISN'i geri yazman lazım. Yani "geçici test" için virginize etmek kötü fikir — geri dönüşü zahmetli.
  • TPROT / secure boot aktifse bazı MG1'lerde clear ISN doğrudan çalışmaz, önce unlock gerekir.

Sana samimi tavsiyem: Sadece bir şeyi test etmek için 2019 G14 B58 DME'sini virginize etme. Yaptığın işin ne olduğunu söylersen (ör. "başka VIN ile ISTA'da test yapmak istiyorum", "başka araca takacağım", "cluster VIN uyuşmazlığını çözmek istiyorum") çok daha az riskli bir yol önerebilirim — çünkü çoğu senaryoda VIN'i DME'de değiştirmene hiç gerek yok.

Bir de netleştir:

  • Elindeki tool tam olarak hangisi? (PCMflash / Autotuner / Flex / Bitbox / başka?)
  • DME'yi bench'e alabiliyor musun, yoksa sadece OBD üzerinden mi çalışıyorsun?
  • Amacın gerçekten ne — bunu bilirsem virginize etmeden çözülüp çözülemeyeceğini söylerim.
 

Post #14

MultiProg ile MG1CS003 üzerinde yapabileceğin işlemleri kısaca özetleyeyim, sonra risklere geleyim.

Bağlantı şekli
MG1'de MultiProg bench modunda çalışır — OBD değil. Yani DME'yi araçtan sökmen, kapağı açıp bench kablosunu (MG1/MD1 adaptörü + güç) ilgili pinlere bağlaman gerekir. Programlayıcıyla birlikte gelen MG1 bench şeması esas alınmalı; yanlış pin = kalıcı hasar riski.

Sıfırlama (virginize) mantığı
MultiProg'un MG1/MD1 menüsünde tipik olarak şu seçenekler bulunur:
  • Read ISN — mevcut ISN'i çıkarır (yeni araca takacaksan şart)
  • Read INT / EXT Flash + EEPROM — tam yedek (bu şart, atlama)
  • Virginize / Clear VIN / Reset ISN — DME'yi bakir hale getirir; VIN, ISN ve pairing verileri temizlenir
  • Write ISN / Write VIN — hedef araç verilerini yazma

Virginize işleminden sonra DME artık "yeni" gibi davranır; VIN alanı boş olduğu için E-Sys/Tool32 üzerinden 0x2E F190 yazımı kabul edilir. Senin karşılaştığın "conditionsNotCorrect" hatasının çözümü tam olarak budur.

Riskler — bunlar ciddi
  • ISN kaybı: Virginize'den önce ISN'i mutlaka okuyup güvenli yere kaydet. ISN kaybolursa DME orijinal araca bir daha hiçbir şekilde geri bağlanamaz — FEM/BDC ile eşleşmez, motor çalışmaz. CAS/FEM değiştirmek gerekir.
  • Yedek olmadan yazma: INT flash + EXT flash + EEPROM'un tamamının okunmuş ve doğrulanmış yedeği olmadan hiçbir yazma işlemi yapma. Okuma bittiğinde iki kez oku ve iki dosyayı karşılaştır (byte-by-byte aynı olmalı).
  • Besleme: Bench'te regüle laboratuvar güç kaynağı kullan (12.0–13.5 V, en az 5 A). Voltaj düşüşü yazma sırasında DME'yi tuğlaya çevirir. USB hub'dan besleme yok.
  • Pin hatası: MG1 bench pinout'unda GND/VBAT karışırsa TC298 anında ölür. Şemayı iki kez kontrol et.
  • Yanlış dosya profili: MultiProg'da mutlaka MG1CS003 profilini seç, CS201 veya CS182 değil. Yanlış profil yanlış adrese yazar.

Senin durumun için pratik akış
Aslında sadece "geçici VIN testi" yapmak istiyorsan bench'e inmek aşırı riskli. Aracın orijinal DME'sini virginize edersen ISN'i tekrar aynı DME'ye yazsan bile araç hâlâ orijinal VIN'i beklediği için FEM ile yeniden pairing gerekebilir; kısa bir test için çok büyük bir adım. E-Sys/ISTA üzerinden hedeflediğin kontrolü başka bir yolla yapmak mümkün mü? Tam olarak neyi doğrulamak istediğini yazarsan (ör. belirli bir kodlama, adaptasyon, servis fonksiyonu) daha güvenli bir yol önerebilirim.

Yine de bench'e girmek istersen, MultiProg'un tam olarak hangi sürümünü ve hangi bench adaptörünü kullanacağını yaz — MG1 menüsündeki adımlar sürüme göre farklılık gösteriyor.
 
Activity
So far there's no one here