6/27/2017

Fgtech, Ktag, Kess V2 bench unlock & flash PCR 2.1

This is a thread- “100% tested /worked bench unlock and flashing (read and write ) on pcr2.1”, posted in digital-kaos.co.uk.



Good information, so i share this thread again.



No one but yourself should take responsibility of what you will try.



Big thanks to gzk in France did the following write-up of reviews of pcr2.1 bench unlock and flashing. Here you go.



(src: http://www.digital-kaos.co.uk/....-bench-unlock-and-flashing-(read-and-write-)-on-pcr2-1)





i have past last week trying many thinks on pcr2.1 and bench flashing .
everything wrote below is tested and confirmed working by me on 4 ecus /cars, only on Chinese clone not reworked unit : fgtech v54, ktag 6.070, kess v2 4.036, ksuite up to 2.15


pcr 2.1 need to be as you know unlocked before writing .


I prefer ksuite to work on this ecu (kess or ktag) , ksuite seem to be more stable than fgtech on pcr but work too : i get error with fgtech on one pcr2.1 , i don't know why , and no problem with ksuite .
Same day i try another pcr with fgtech and no problem , the one fgtech don't want to work with work flawlessly with ksuite and car run ok .


So if you have both tools , prefer ksuite seem to be more stable .


After you get you ecu unlocked in boot mode , with fgtech just remove boot and left pin connection , and read or write on bench .


On ksuite tools , you can't read or write with ktag , only unlock . (alientech need to work on it...)
with kess it's ok , BUT , you can't use the tricore module !


The problem is that the harness is plugged in the tricore module . so you have to build your own bench cable : just get a obd female plug on a scrapyard , and wire +12 gnd and can h/l (kline is not used but you can wire it it will make a universal bench cable) .


The trick to get communication error free on both fgtech and kess cable is to use a strong external psu .


when the tool id or read or write the ecu , the ecu will perform a kind of reset , and the big cap inside the ecu will go charging , causing a drop in voltage if your psu isn't strong enough to handle it . THAT WILL CAUSE THE COMM ERROR . That's the only thing you have to take care .


when i made test with many little psu (like one you get with your tools) i have seen 7 volts drop some time , so the ecu is shutting down and no comm .


you can use computer atx psu modded to work on bench (green wire plugged on ground to power on ) i think anything that can provide +12v 2A will be ok . i didn't need more than 12v just a stable 12V . 14v unstable will not be ok


that's why on the car you have no problem , car battery can handle the cap charging current .


There is no immo caused comm error on this ecu , psu is the problem !!


So in conclusion : good psu and obd home made bench cable , remove tricore module on kess = 100% tested bench flashing solution for pcr2.1 .


blog.obdii365.com



6/01/2017

How to use Fgtech Galletto Clone to write safety PCR 2.1

Here is the instruction on writing stately PCR 2.1 with Fgtech Galletto 4 V54 master clone for those who do not have original tools.  All you need it's UPA USB and Galletto V54 China clone!

Credits to Mr. mercas who made this tutorial.


On forum exist a lot of threads with bricked ecu's because Galletto,Kess or other tool don't unlock ok every time this ecu on bootmode,

or ecu was already unlocked by another tuner.

This steps were tested by 3 PCR ECU's from 3 different years and all was ok.




How to write safety PCR 2.1 with Galletto v54 China clone!



1. Read flash OBD with fgtech v54 clone;



2 Open ecu Carefully!! and put it back to car to test if you don't destroy it when you open;




3 read eeprom 25640 with 2 different programmers(i used upa and xprog M), and compare it;




4 unlock with program PCR2.1-Simos8 Unlock 1.1 25640 eeprom (Search it on MHHAUTO forum);




5 solder eeprom back;




6 start car;




7 go with VCDS look variable Measuring block 497;

If production it's locked;

If sample then unlocked ;




8 read flash again by obd(it will be the same like first read);




9 modify files and make checksum with winOLS;




10 write flash by OBD, if fail, write original without read id data;




Here is a manual way how to do the unlock in Winols:




open the eeprom (25640) on winols

choose the decimal mode

and 16 bit

go to the address 24A

24A 24C 24E and 250

we will calculate this 4 value

you will 65535 - 24A value

write it to 24A

for example on my file 17052 is 24A value

65535 - 17052

48483

you will write 48483 to 24A

the you will do it same for 24C

65535 - 24C = will new value

for example in my file 34224 is 24C value

65535 - 34224 = 31311 is new value for 24C

you will calcuate this 4 value

and save and write the file

after do that

to be sure



calculate the all 4 values ori and tuned