Lada 111 1.6L 16V 2005 year – Immo Off

By on January 9, 2018
repair immobilizer circuit board

 

 

 

 

 

 

 

 

 

Hi!

As the title say, in this writing I will try to show as best I can how to make the immobilizer system off,  or disarm it in the Lada 111 type of car. What is an immobilizer system and what for is it in the car? An immobilizer system or in short “immo” is an anti theft system in modern cars, trucks, bikes etc. As in the upper text described, the main usage is to securing the vehicle from unauthorized driving.




These systems are very complex and hard to crack, but not impossible. In some countries this kind of hacking the immo is forbidden. The very basic but main components are for an immo system:

–              Vehicle key

–              Ignition ring

–              Immo ecu or so called immo box.

immo off ecu

I tried to make a block diagram about a very simple immo system. I hope you got the path. When the key is in the Ignition ring and is turned to ignite position. The immo ecu will request the ID from the key which is inside the key in the so called transponder.

The Immo ecu will check if that key is Key 1, 2, 3 etc. and send the authorization data to the engine ecu. If the engine ecu see an acceptable data got from the immo ecu and that data is correct in his eeprom, than the engine ecu will allow to start the injection sequence etc.

This is a very simple and very basic description about the immo system, so please use It for a basic interpretation only. What will happen if the ecu goes bad and will be interchanged? Or the immo ecu goes bad, or the key is lost or bad… ?

–              You can go to an official service and pay a very high bill for the repair.

–              Go to some other person who can maybe hack all this unit’s and save some money.

Let’s see how this is done on this type of car, the Lada 111. This car have an APS-4 immo ecu and a Bosch 0 261 208 315 engine ecu. From a previous contact with a similar car with the same immo system I know does this engine ecu can be made something like virgin, or to delete the data inside the eeprom of the ecu in a meaning does the ecu wont check for authorization. But in this case you must disconnect the data line between the engine ecu and the immo ecu.

The reason is because, if the data line, so called K line is active between the immo ecu and the engine ecu, the immo ecu will activate the authorization sequence in the engine ecu aven it is deactivated in the engine ecu.

Have in mind does the immo ecu will make any effort to protect he vehicle, and will try to disable whatever he can to protect the vehicle. In today’s modern cars this communication is gone between a computer network inside the car. I won’t take attention to the APS-4 immo box, just cut the K line wires and the immo system is no more able to take control over the engine ecu or whatever ecu. My first step was to take out the engine ecu from the vehicle and locating the eeprom inside.

immo off

bosch motronic

how to repair immobilizer

how to fix immobilizer

We have to desolder this eeprom but there is a hidden big problem, which could kill the ecu.

Here is the problem:

how to fix and repair immobilizer

This is also a situation where novices make common mistake, when it comes to soldering/desoldering smd parts. After the soldering/desoldering task the whole unit can be killed.

What’s the problem?

This is a double side pcb. Full filled with small smd parts on both side. If we look closer we can see the eeprom is direct above the cpu. We have also heavy GND circuit cupper traces on the pcb which will act as a heat sink. In this case, the possibility not to overheat the pcb and the cpu are very small.




There are several possibility how to read this smd eeprom.

  1. Unsolder with hot air – unsafe high risk to overheat and kill the unit, but with care it is safe.
  1. Unsolder with some soldering stick – not an option for me, because a high risk of possibility to lift the trace.
  1. Read the eeprom incircuit – most safe technique not to overheat or crack the trace,

but there is a high risk to get  a corrupted data reading or writing. I went to No 1 technique but with care. Here is what I did:

repair immobilizer circuit board

I used the housing of the ecu as a heat sink. Put it on a way on the pcb does the cpu are completely covered with the aluminum case. So the heat will quickly take from the cpu, but be warned! Even with this technique there is a risk to overheat!

Adding much flux paste to the legs of the eeprom or whatever component you deal with, is a good idea. The flux paste will help to concentrate the heat to the legs and the attacked region will not cool down quickly as it would without adding flux. Every time when it comes to desoldering smd parts, preheat the pcb. In this case I don’t used a pcb pre-heater because the parts which are on the other side of the pcb, but  I pre-heated the region around the eeprom with my hot air desoldering gun.

Now, when we have the eeprom out of the pcb, we have to read, change the dump* and write back the new dump into the eeprom and solder the eeprom back to the pcb. Dump – is a synonym of the content of an eeprom or flash memory. For reading this type of eeprom you can use something like the MiniPro TL866 or many other programmer will support this eep.

The content modification you can do in a hex editor manual or you can use commercial software like the ECU Vonix some version or so. I don’t like that commercial software because they make stuff automatically and are very universal tools. Universal tool are good but they can make thing bad. But Ecu Vonix is a good tool for simple vehicles. Will do the job for sure.

Here is a part of the unmodified eeprom content:

car eeprom hex code

I like my HxD hex editor. As you can see this eeprom is pretty empty. The immo data is written at the offset H20 and H40. Ok, I won’t go into the deep in the technique how to mod this data, bat use a software as I mentioned and you will do the job on this type of car and on similar too.

Load the dump into the EcuVonix software and let them do the mod. Save the new file and program it back to the eeprom.

UPPS!

Here we come to another tricky step, what could also kill the ecu. We are talking more about killing today than repairing, do you asked yourself, “will this car run again?” So, what‘s the problem? You programmed the eeprom and must to try somehow the content if it is working. Ok, you will solder it back, but what if the content is actually not working?

And you have to correct something in the dump and write again the dump to the eeprom? You have to go again into the risk to overheat the pcb and maybe kill the ecu etc…

That’s a bit frustrating or? Here is how I go around situations like this, and I can try many times the dump until I success.

One picture talks 1000 words:

how to program car eeprom ic

I hope you got the point. With this “adapter” I can many times program the eeprom without to soldering/unsoldering etc..

Ok, the dump was created with the EcuVonix software, the immo is now disarmed in the engine ecu and the engine ecu won’t request any more for any authorization. Now we have to cut the wire on the immo ecu. These wires are actually the network wire what is used by all the computers inside the car to communicate with each other.

If you leave this wires as they are, the immo ecu will immediately lock down the engine ecu when you turn the key in ignite position. That means, the engine ecu will again ask for ignite authorization etc.

Here is what wire must be cut and  wire it together. That is the so called K line wire. You can simply cut them and that would be enough, but if you don’t wire them together than you can’t any more make a diagnostic on this vehicle. Your diagnostic scanner tool cant communicating any more with the ecu’s inside the car, because the network is in open circuit stage.

This is the connector on the immo ecu, the PIN9 and PIN18 must be shorted.

immo ecu

After this mod, put back the connector to the immo ecu and enjoy in your work. Congratulation, your immobilizer system is disarmed.

I hope you enjoy this tutorial and will save lot of repair time.

 

This article was prepared for you by Christian Robert Adzic from Novi Knezevac-Serbia.




Please give a support by clicking  on the social buttons below. Your feedback on the post is welcome. Please leave it in the comments.

P.S-  If you enjoyed reading this, click here to subscribe to my blog (free subscription). That way, you’ll never miss a post. You can also forward this website link to your friends and colleagues-thanks!

Note: You can check his previous post in the below link:

http://jestineyong.com/manifold-absolute-barometric-pressure-sensor-testing/

 

Likes(78)Dislikes(0)

18 Comments

  1. Parasuraman

    January 9, 2018 at 1:20 pm

    Very comprehensive info!

    Likes(5)Dislikes(0)
  2. James

    January 9, 2018 at 5:05 pm

    Yea, good work, makes you wonder if there's another way to just by-pass the alarm system, like our pontiacs here in the states, you have to cut a wire and put a resistor in the circuit, I did one and it worked like a charm'.

    Likes(4)Dislikes(0)
    • Chris

      January 11, 2018 at 3:10 am

      Hi!
      Thanks for supporting my article.
      What type of alarm system is it in your Pontiac?
      What model, year is that Pontiac?
      Is that alarm system a OEM system in that vehicle or an aftermarket?

      Just for info:
      The immo system and the alarm system are not the same think.
      In modern cars, that two systems are close the same but still not the same think.

      My best regards.

      Likes(2)Dislikes(0)
  3. suranag Electronics

    January 9, 2018 at 5:43 pm

    hi Christian Robert,

    Grate Job,
    Yes Very nice.

    Likes(1)Dislikes(0)
  4. AdamS

    January 9, 2018 at 6:43 pm

    And of course, don't forget to let your insurance company know that you have made this modification, otherwise your insurance will no longer be valid.

    Likes(2)Dislikes(0)
    • Chris

      January 10, 2018 at 11:18 pm

      Hi!
      Thanks for supporting my article.
      Here in my areal the insurance have nothing to do with this mod.
      If you do something like this, you should agree the consequences with the law.

      My best regards.

      Likes(1)Dislikes(0)
  5. Albert van Bemmelen

    January 10, 2018 at 2:39 am

    Interesting fix/repair but seeing the prices asked for the suggested EcuVonix software (400 to 698 Euro?) it is not likely a affordable method to choose from if intended for only a one time operation. Or is there a free or more low budget software version to start with?

    Likes(3)Dislikes(0)
    • Chris

      January 10, 2018 at 11:03 pm

      Hi!
      Thanks for supporting my article.
      Of course, the price is high if somebody wish only one time use it and more worse is if they wont get income (financial) from the mentioned software.
      There are lot of software out on the net who can do the job too, even for free.
      But, if you ask on forum's for help and post the eep dump there are we too to help for free.
      For me is not a problem to mod the dump and send it back to the user for free.

      Many of as do such of thinks manually, but in real, a tool for approximately 650 euro is not a high price for a professional job.

      My best regards.

      Likes(1)Dislikes(0)
      • Albert

        January 14, 2018 at 9:43 pm

        Thanks for your reply Chris. I understand that without the EcuVonix software or some other kind of special softwaretool it can't be done. Taking in account that in a code with more than FFFFFFFFFFFFFFFFFFFF (20 x F hex) as a maximum number that already means at least 1.2089258196146E to the exponent of 24 of decimal possibilities. And because also other special characters could be used that even widens the number of possible wrong codes. Whithout any given method or algoritmic explanation the article only tells us that it is impossible to do this with just a Hex editor? It is just like hacking the Eeprom of a protected Lithium Battery without any expensive software tool. Also impossible (luckily they now sell Lithium-ion BMS charging boards without time and charging counting Eeproms, See for instance: https://nl.aliexpress.com/item/4A-5A-PCB-BMS-Protection-Board-For-4-Packs-4S-18650-Li-ion-lithium-Battery-Cell/32656147875.html?spm=a2g0z.search0104.3.9.6Rkkq5&ws_ab_test=searchweb0_0,searchweb201602_2_10152_10151_10065_10344_10068_10342_10343_10340_10341_10084_10083_10613_10304_10615_10307_10614_10301_10059_10314_10534_100031_10604_10103_10142,searchweb201603_25,ppcSwitch_5&algo_expid=8cb5460d-4e34-4c5f-a426-ef5d2e57380d-1&algo_pvid=8cb5460d-4e34-4c5f-a426-ef5d2e57380d&priceBeautifyAB=0 ).

        Likes(1)Dislikes(0)
        • Albert van Bemmelen

          January 14, 2018 at 10:53 pm

          By-the-way: In this case there are even more than 20 F's in the protected code, and besides also lines 70 and 90 contain code too.

          Likes(1)Dislikes(0)
  6. Mihai

    January 10, 2018 at 2:41 am

    Hello, Good job sir !
    Very usefull information.

    Likes(1)Dislikes(0)
  7. tino choolun

    January 10, 2018 at 1:15 pm

    hi
    good job and info
    how can used the ecuvomix to virgin a sagem 2 2000 and reprogram it ?
    again a crazy job
    thumb up

    Likes(1)Dislikes(0)
    • Chris

      January 10, 2018 at 11:14 pm

      Hi!
      Thanks for supporting my article.
      I assume you have that Sagem from some type of the PSA family of car and the name of the ecu is actually Sagem S2000.
      I also assume you wish also do the immo off.

      In this case you could have the eeprom 25080 or 95080.

      You have to read out the eeprom and follow my text but don's short out anything as I described.

      Also follow the instruction from EcuVonix.

      My best regards.

      Likes(2)Dislikes(0)
  8. Robert Calk

    January 10, 2018 at 9:59 pm

    Good job, Christian. The best way to desolder the IC in that situation is to use Chip Quik. You can save money by buying the Chip Quik solder by itself and using your own flux and cleaning supplies.

    Likes(2)Dislikes(0)
    • Chris

      January 11, 2018 at 8:47 pm

      ChipQuik Alloy is a very good think and I like that product, but it is very hard in my area to get one...

      My best regards.

      Likes(1)Dislikes(0)
  9. Yogesh Panchal

    January 11, 2018 at 6:29 pm

    Christian,
    Thanks for excellent information.

    Likes(1)Dislikes(0)
  10. Lad

    January 12, 2018 at 5:21 am

    Very good article. Thank you.
    Do you have any experience with Fiat Doblo transponder programming? I think it has a transponder immo ID48. And it is a part of car key.
    I think I must program that ID48 in case I lost the original immo. How can it be programmed or how to make a dump? ID48 is RFID .Thank you

    Likes(1)Dislikes(0)
    • Chris

      January 14, 2018 at 8:11 am

      Hi!
      Thanks for supporting my article.
      So, it is a different story.
      You must program a new transponder ic.
      I'm not sure but I think the so called ZedBull device can make a copy of your key.
      But SBB can for sure.

      I think, it is more worth to make the immo off in your car if it is an acceptable solution for you.
      I think in immo off direction because if you need to buy a programming
      device + trnasponder ic (several pcs.) that will be to expensive for only one car. Maybe if you go to a pro person would be a bit cheaper but the most cheap and 100% working solution will be the immo off.

      I hope I helped you.
      My best regards.

      Likes(1)Dislikes(0)

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.