PDA

View Full Version : Help: EZS W203 MCU repair 68HC08AZ60 1J35D



kanzus
3rd March, 2010, 12:03 PM
I worked last days with electronis MB as well, and get more experience about EZS/EIS ESL ECU and smart Keys.
I bught several eprom/MCU programmers: motorola and NEC, also AK400.
I also got ECU/EZS/ESL of C32 amg w203. I can read :
- ECU serial eprom 5p08c3, (R/W ok)
- ESL MC68HC05E6 MASK (0G72G) (Read OK, write NOK) and
- EZS/EIS with 2 motorola MCUs: 68HC08AZ60 (1J35D) read/write ok but lost all data: motorola MCU with 1j35d mask are protected and ROM based whitch differs from other MC08 MCU family as 2j72y ..

So programming R/W 1j35d MCU should be done only on board, never take off MCU to program, if you take it off (desolder), it looses all data, and unfortunatly that what happens to me :-(

I tryed another type of EZS, I take one from CLK 209, it's HC912 based motorola MCU, I succeed read/write data, and I test odo adjusting and work well.

Can you help me to insert data in w203 EZS again, do someone have ezs dump of w203 that can give to me ?

PremierD
3rd March, 2010, 12:31 PM
I worked last days with electronis MB as well, and get more experience about EZS/EIS ESL ECU and smart Keys.
I bught several eprom/MCU programmers: motorola and NEC, also AK400.
I also got ECU/EZS/ESL of C32 amg w203. I can read :
- ECU serial eprom 5p08c3, (R/W ok)
- ESL MC68HC05E6 MASK (0G72G) (Read OK, write NOK) and
- EZS/EIS with 2 motorola MCUs: 68HC08AZ60 (1J35D) read/write ok but lost all data: motorola MCU with 1j35d mask are protected and ROM based whitch differs from other MC08 MCU family as 2j72y ..

So programming R/W 1j35d MCU should be done only on board, never take off MCU to program, if you take it off (desolder), it looses all data, and unfortunatly that what happens to me :-(

I tryed another type of EZS, I take one from CLK 209, it's HC912 based motorola MCU, I succeed read/write data, and I test odo adjusting and work well.

Can you help me to insert data in w203 EZS again, do someone have ezs dump of w203 that can give to me ?

I beg to differ mate ... I always remove 908 (1j35d)..for progamming... straight into socket on ETL programmer ,read/write....and resolder ...so I don't know how you read it ...but thats the only safe way to do it ....

kanzus
3rd March, 2010, 02:49 PM
Could you tell me which programmer do you use ??
I used AK400 on board programming using pin 2, 3, 26 and +/- pins.

Here is extaction from AK500 manual (close to AK400):

4. HC908 Series MCU: in accordance with the wiring
diagram to support read and write EEPROM, a FLASH also
supports reading and writing 2J74Y/4J74Y. 1J35D only
allowed to deliver the ROM, can not write. (EIS's 1J35D
chip can be used in place of 2J74Y or 4J74Y).

Could you PM 1j35d dump w203 Please?

Thanks in advance.

kanzus
4th March, 2010, 12:09 PM
Could someone explain how HC08AZ60 bite protection works ?
What's the role of security bit?

Qrius
4th March, 2010, 12:32 PM
Could you tell me which programmer do you use ??.


I straight into socket on ETL programmer....

Your question was allready answered :devil:

PremierD
4th March, 2010, 12:42 PM
Could someone explain how HC08AZ60 bite protection works ?
What's the role of security bit?

It's like chip and Pin mate ... so you are allowed to access the MCU....NO CORRECT BYTES ....No access....

rwgodoy
11th March, 2010, 03:25 PM
I having problems to read this MCU with ETL. The message is
"PTA0" must be in "high" state

I don't know how to resolve it

rwgodoy
15th March, 2010, 10:59 PM
I Can read this MCU with ETL now.
To read this device, I plug the pin of oscilloscope into pin 59 (OSC1) and read, and the device is Unsecured !!! :dontknow:

Don't ask me why! but it resolves!!!

twrch
16th March, 2010, 12:19 AM
I Can read this MCU with ETL now.
To read this device, I plug the pin of oscilloscope into pin 59 (OSC1) and read, and the device is Unsecured !!! :dontknow:

Don't ask me why! but it resolves!!!


It sounds like you pulled the necessary line *low* so that you were able to read the MCU. You can not unsecure an MCU with an external electrical signal. If it is truly secured, then you *will* be able to read it, but you will be reading garbage!

harryauto
18th March, 2010, 10:16 PM
E-mail or skype to me , and i have this car all data and must be work ,
E-mail : harry@harryauto.com
Skype : harryauto

highline
19th March, 2010, 03:21 AM
Hello
If you get stuck with the adjustment, you can send me the EZS, ESL, MSG, and the keys and I learn to you at this.
Marco
Ps: The clone AK400 China's waste, have had to test two.

kanzus
22nd March, 2010, 10:22 AM
Hello
If you get stuck with the adjustment, you can send me the EZS, ESL, MSG, and the keys and I learn to you at this.
Marco
Ps: The clone AK400 China's waste, have had to test two.

AK400 is really a waste ef money, I tryed it and all what you can do with it is to test Smart keys using infrared, that's all.
I read couple of EZS w203 and w209 and it damages both of theim, i payed it about 650$ on Eb*y, and must buy two EZS right now GRRRRRRRRR....

I'm really fed up with cloned chinese products, if you wwant to work fine, everyone should invest proportional money ;-)