<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://opengk.org:443/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Dmg210</id>
	<title>OpenGK - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://opengk.org:443/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Dmg210"/>
	<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Special:Contributions/Dmg210"/>
	<updated>2026-09-18T10:40:19Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.0</generator>
	<entry>
		<id>https://opengk.org:443/index.php?title=Bootstrap_Loader&amp;diff=1010</id>
		<title>Bootstrap Loader</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Bootstrap_Loader&amp;diff=1010"/>
		<updated>2026-07-06T08:52:12Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Entering the BSL mode (2.0L) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Stub}}&lt;br /&gt;
&lt;br /&gt;
Bootstrap Loader (BSL) on the C166 MCUs allows to execute code in memory, bypassing code stored on the EEPROM.&lt;br /&gt;
&lt;br /&gt;
This is often used to flash regions of memory inaccessible through OBD2, such as the bootloader. Most notable case would be removing the [[immobiliser]], or performing a ca663056-&amp;gt;ca663057 upgrade, which requires changing the bootloader.&lt;br /&gt;
&lt;br /&gt;
To enter BSL mode, you must ground the BOOT pin and then feed power to the ECU, which will make the CPU wait for input over serial port instead of executing code stored on the flash memory. Then, typically a small loader is uploaded which later facilitates upload and execution of the proper BSL program, which will offer ways to manipulate memory. &lt;br /&gt;
&lt;br /&gt;
[https://github.com/dante383/gkflasher GKFlasher] supports BSL mode.&lt;br /&gt;
&lt;br /&gt;
== Entering BSL mode (2.0L) ==&lt;br /&gt;
[[File:Boot pin ziome3eg.png|thumb|BOOT pin]]&lt;br /&gt;
&lt;br /&gt;
=== Non-immo ECUs ===&lt;br /&gt;
&lt;br /&gt;
# Connect ECU pins 3, 14, 21 and 22 to +12V.&lt;br /&gt;
# Connect [[K-Line]] per [[Siemens 5WY 2 Connector Pinout|ECU pinout.]]&lt;br /&gt;
# Pull down the BOOT pin to Ground through a 10kΩ resistor. (Most V6 ECU&#039;s have the resistor onboard). &lt;br /&gt;
# Connect power and ground to the ECU.&lt;br /&gt;
# ECU is now ready for BSL input - you can press any button in the BSL tab in GKFlasher.&lt;br /&gt;
&lt;br /&gt;
=== Immo ECUs ===&lt;br /&gt;
&lt;br /&gt;
# Connect ECU pins 3, 14, 21 and 22 to +12V.&lt;br /&gt;
# Connect K-Line (pin 77) per [[Siemens 5WY 2 Connector Pinout|ECU pinout]]. &lt;br /&gt;
#Attach a 470Ω resistor on the [[W-Line|W-Line&amp;lt;small&amp;gt;(? citation needed)&amp;lt;/small&amp;gt;]].&lt;br /&gt;
#Splice [[K-Line]] into [[K-Line]] on the ECU header - if you&#039;re using a Y-split OBD2 cable, that&#039;d be [[Data link connector (OBD2)|pin 9]].&lt;br /&gt;
# Pull down the BOOT pin to Ground through a 10kΩ resistor.&lt;br /&gt;
# Connect power and ground to the ECU.&lt;br /&gt;
# ECU is now ready for BSL input - you can press any button in the BSL tab in GKFlasher.&lt;br /&gt;
[[File:Bsl pins dmg210.png|thumb]]If the method above does not work, try the following:&lt;br /&gt;
&lt;br /&gt;
# Connect ECU pins 3, 14, 21 and 22 to +12V.&lt;br /&gt;
# Connect K-line (OBD pin 7) to W-Line on the ECU header (pin 47).&lt;br /&gt;
# Pull down the BOOT pin (pin 28 of the flash chip) to Ground through a 10kΩ resistor.&lt;br /&gt;
# Connect power and ground to the ECU.&lt;br /&gt;
# ECU is now ready for BSL input - you can press any button in the BSL tab in GKFlasher.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Bootstrap_Loader&amp;diff=1009</id>
		<title>Bootstrap Loader</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Bootstrap_Loader&amp;diff=1009"/>
		<updated>2026-07-06T08:51:40Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Non-immo ECUs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Stub}}&lt;br /&gt;
&lt;br /&gt;
Bootstrap Loader (BSL) on the C166 MCUs allows to execute code in memory, bypassing code stored on the EEPROM.&lt;br /&gt;
&lt;br /&gt;
This is often used to flash regions of memory inaccessible through OBD2, such as the bootloader. Most notable case would be removing the [[immobiliser]], or performing a ca663056-&amp;gt;ca663057 upgrade, which requires changing the bootloader.&lt;br /&gt;
&lt;br /&gt;
To enter BSL mode, you must ground the BOOT pin and then feed power to the ECU, which will make the CPU wait for input over serial port instead of executing code stored on the flash memory. Then, typically a small loader is uploaded which later facilitates upload and execution of the proper BSL program, which will offer ways to manipulate memory. &lt;br /&gt;
&lt;br /&gt;
[https://github.com/dante383/gkflasher GKFlasher] supports BSL mode.&lt;br /&gt;
&lt;br /&gt;
== Entering the BSL mode (2.0L) ==&lt;br /&gt;
[[File:Boot pin ziome3eg.png|thumb|BOOT pin]]&lt;br /&gt;
&lt;br /&gt;
=== Non-immo ECUs ===&lt;br /&gt;
&lt;br /&gt;
# Connect ECU pins 3, 14, 21 and 22 to +12V.&lt;br /&gt;
# Connect [[K-Line]] per [[Siemens 5WY 2 Connector Pinout|ECU pinout.]]&lt;br /&gt;
# Pull down the BOOT pin to Ground through a 10kΩ resistor. (Most V6 ECU&#039;s have the resistor onboard). &lt;br /&gt;
# Connect power and ground to the ECU.&lt;br /&gt;
# ECU is now ready for BSL input - you can press any button in the BSL tab in GKFlasher.&lt;br /&gt;
&lt;br /&gt;
=== Immo ECUs ===&lt;br /&gt;
&lt;br /&gt;
# Connect ECU pins 3, 14, 21 and 22 to +12V.&lt;br /&gt;
# Connect K-Line (pin 77) per [[Siemens 5WY 2 Connector Pinout|ECU pinout]]. &lt;br /&gt;
#Attach a 470Ω resistor on the [[W-Line|W-Line&amp;lt;small&amp;gt;(? citation needed)&amp;lt;/small&amp;gt;]].&lt;br /&gt;
#Splice [[K-Line]] into [[K-Line]] on the ECU header - if you&#039;re using a Y-split OBD2 cable, that&#039;d be [[Data link connector (OBD2)|pin 9]].&lt;br /&gt;
# Pull down the BOOT pin to Ground through a 10kΩ resistor.&lt;br /&gt;
# Connect power and ground to the ECU.&lt;br /&gt;
# ECU is now ready for BSL input - you can press any button in the BSL tab in GKFlasher.&lt;br /&gt;
[[File:Bsl pins dmg210.png|thumb]]If the method above does not work, try the following:&lt;br /&gt;
&lt;br /&gt;
# Connect ECU pins 3, 14, 21 and 22 to +12V.&lt;br /&gt;
# Connect K-line (OBD pin 7) to W-Line on the ECU header (pin 47).&lt;br /&gt;
# Pull down the BOOT pin (pin 28 of the flash chip) to Ground through a 10kΩ resistor.&lt;br /&gt;
# Connect power and ground to the ECU.&lt;br /&gt;
# ECU is now ready for BSL input - you can press any button in the BSL tab in GKFlasher.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=989</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=989"/>
		<updated>2026-01-19T10:41:04Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Bootloader &amp;amp; UIF */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
&lt;br /&gt;
=== Memory offset &amp;amp; bin offset ===&lt;br /&gt;
Through OpenGK wiki and projects, you&#039;ll often find the terms memory offset, and bin offset. &lt;br /&gt;
&lt;br /&gt;
You might notice that memory offset is usually either 0x40000 or 0x80000 larger than bin offset when referring to the same spot (such as the calibration zone). &lt;br /&gt;
&lt;br /&gt;
Bin offset is referring to the position in your .bin file - and the EEPROM. Memory offset is referring to the CPU offset - such as when reading using ReadMemoryByAddress. &lt;br /&gt;
&lt;br /&gt;
This is because of the c166 memory layout, depending on the installed EEPROM.   &lt;br /&gt;
&lt;br /&gt;
2mbit chips will have a 0x40000 memory offset, 4mbit chips - 0x80000 and 8mbit chips - 0.  &lt;br /&gt;
&lt;br /&gt;
While it can be seen clearly in the tables below, a quick example:  &lt;br /&gt;
&lt;br /&gt;
* if you open a .bin file for a 2mbit SIMK41, you&#039;ll find that the calibration zone starts at 0x8000. If you wanted to use [[CAN Calibration Protocol|CCP]] or ReadMemoryByAddress to read it out from the ECU, you&#039;d adjust this address to 0x8000 + 0x40000 = 0x48000.&lt;br /&gt;
* if you open a .bin file for a 4mbit SIMK43, you&#039;ll find that the calibration zone starts at 0x10000. If you wanted to use [[CAN Calibration Protocol|CCP]] or ReadMemoryByAddress to read it out from the ECU, you&#039;d adjust this address to 0x10000 + 0x80000 = 0x90000.&lt;br /&gt;
* If you open a .bin file for a 4mbit SIMK43 and find the calibration zone checksum area stop address, chances are it&#039;ll be equal to 0x98000. If you wanted to find that location in your bin file, you&#039;d subtract the bin offset: 0x98000 - 0x80000 = 0x18000 &lt;br /&gt;
&lt;br /&gt;
=== Regions ===&lt;br /&gt;
Both units memory can be separated into 5 regions:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
All provided offsets are in hex&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!Memory start&lt;br /&gt;
!Memory end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!Memory start&lt;br /&gt;
!Memory end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; |0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; |3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E7FF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E7FF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |XRAM&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |2 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |EF00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |EF00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |CAN1&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |256 bytes&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F200&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F200&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |ESFR&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |512 bytes&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F600&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FBFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F600&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FBFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |Internal RAM&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |1.5 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FC00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FC00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |Internal SFRs&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |1 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FD00&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FF55?&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FD00&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FF55?&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |INT_RAM_BIT&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |256 bytes&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; |88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; |97FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; |90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; |AFFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; |A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; |11FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Memory start&lt;br /&gt;
Bin start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Memory end&lt;br /&gt;
Bin end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 50000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 5FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|87FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIM2K-47 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Memory start&lt;br /&gt;
Bin start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Memory end&lt;br /&gt;
Bin end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 52000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 5EFF0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 52 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot; |82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot; |87FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot; |Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot; |24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 92000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 9EFF0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 52 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key verification enabled flag]]&lt;br /&gt;
|0x3E00&lt;br /&gt;
|1&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=00}}&lt;br /&gt;
|Flag determining whether the ECU should ask for KWP authorization key. 0x00 - security access verification enabled, 0xFF - disabled&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]: Siemens level access&lt;br /&gt;
|0x3F5C&lt;br /&gt;
|8&lt;br /&gt;
|{{HexConverter|hex=46A019B2CEC64252|default-display=hex}}&lt;br /&gt;
|Seed and key (4 bytes each) for the highest level of access. $27 SecurityAccess: 0xFD for requesting seed, 0xFE for sending key&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMxxDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3037303431353132|default-display=ascii}}&lt;br /&gt;
(2007, April 12th)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified. xx is unknown&lt;br /&gt;
|-&lt;br /&gt;
|ECU lock status flag&lt;br /&gt;
|0x3FBE&lt;br /&gt;
|1&lt;br /&gt;
|{{HexConverter|hex=0x00|default-display=hex}}&lt;br /&gt;
|Flag determining whether the ECU is locked. 0x00 by default, setting it to 0xFF will allow to read the whole ECU including bootzone over KWP2000&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32 kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - INT_RAM [15872]&lt;br /&gt;
* 0xFD00 - INT_RAM_BIT [256]&lt;br /&gt;
* 0xFF800 - RAM [2048]&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET (within RAM)&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block for CCP within bootloader 2&lt;br /&gt;
* 0x3000000 - FLASH_DR [65520]&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[Chassis identifiers|Chassis identifier]]&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;br /&gt;
[[Category:Siemens L4 2.0L]]&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=965</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=965"/>
		<updated>2025-12-07T15:18:49Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
&lt;br /&gt;
=== Memory offset &amp;amp; bin offset ===&lt;br /&gt;
Through OpenGK wiki and projects, you&#039;ll often find the terms memory offset, and bin offset. &lt;br /&gt;
&lt;br /&gt;
You might notice that memory offset is usually either 0x40000 or 0x80000 larger than bin offset when referring to the same spot (such as the calibration zone). &lt;br /&gt;
&lt;br /&gt;
Bin offset is referring to the position in your .bin file - and the EEPROM. Memory offset is referring to the CPU offset - such as when reading using ReadMemoryByAddress. &lt;br /&gt;
&lt;br /&gt;
This is because of the c166 memory layout, depending on the installed EEPROM.   &lt;br /&gt;
&lt;br /&gt;
2mbit chips will have a 0x40000 memory offset, 4mbit chips - 0x80000 and 8mbit chips - 0.  &lt;br /&gt;
&lt;br /&gt;
While it can be seen clearly in the tables below, a quick example:  &lt;br /&gt;
&lt;br /&gt;
* if you open a .bin file for a 2mbit SIMK41, you&#039;ll find that the calibration zone starts at 0x8000. If you wanted to use [[CAN Calibration Protocol|CCP]] or ReadMemoryByAddress to read it out from the ECU, you&#039;d adjust this address to 0x8000 + 0x40000 = 0x48000.&lt;br /&gt;
* if you open a .bin file for a 4mbit SIMK43, you&#039;ll find that the calibration zone starts at 0x10000. If you wanted to use [[CAN Calibration Protocol|CCP]] or ReadMemoryByAddress to read it out from the ECU, you&#039;d adjust this address to 0x10000 + 0x80000 = 0x90000.&lt;br /&gt;
* If you open a .bin file for a 4mbit SIMK43 and find the calibration zone checksum area stop address, chances are it&#039;ll be equal to 0x98000. If you wanted to find that location in your bin file, you&#039;d subtract the bin offset: 0x98000 - 0x80000 = 0x18000 &lt;br /&gt;
&lt;br /&gt;
=== Regions ===&lt;br /&gt;
Both units memory can be separated into 5 regions:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
All provided offsets are in hex&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!Memory start&lt;br /&gt;
!Memory end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!Memory start&lt;br /&gt;
!Memory end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; |0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; |3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E7FF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E7FF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |XRAM&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |2 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |EF00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |EF00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |CAN1&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |256 bytes&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F200&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F200&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |ESFR&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |512 bytes&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F600&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FBFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F600&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FBFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |Internal RAM&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |1.5 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FC00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FC00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |Internal SFRs&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |1 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FD00&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FF55?&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FD00&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FF55?&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |INT_RAM_BIT&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |256 bytes&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; |88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; |97FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; |90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; |AFFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; |A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; |11FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Memory start&lt;br /&gt;
Bin start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Memory end&lt;br /&gt;
Bin end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 50000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 5FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|87FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIM2K-47 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Memory start&lt;br /&gt;
Bin start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Memory end&lt;br /&gt;
Bin end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 52000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 5EFF0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 52 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot; |82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot; |87FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot; |Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot; |24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 92000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 9EFF0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 52 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key verification enabled flag]]&lt;br /&gt;
|0x3E00&lt;br /&gt;
|1&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=00}}&lt;br /&gt;
|Flag determining whether the ECU should ask for KWP authorization key. 0x00 - security access verification enabled, 0xFF - disabled&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]: Siemens level access&lt;br /&gt;
|0x3F5F&lt;br /&gt;
|8&lt;br /&gt;
|{{HexConverter|hex=46A019B2CEC64252|default-display=hex}}&lt;br /&gt;
|Seed and key (4 bytes each) for the highest level of access. $27 SecurityAccess: 0xFD for requesting seed, 0xFE for sending key&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMxxDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3037303431353132|default-display=ascii}}&lt;br /&gt;
(2007, April 12th)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified. xx is unknown&lt;br /&gt;
|-&lt;br /&gt;
|ECU lock status flag&lt;br /&gt;
|0x3FBE? (lost during a page edit)&lt;br /&gt;
|1&lt;br /&gt;
|{{HexConverter|hex=0x00|default-display=hex}}&lt;br /&gt;
|Flag determining whether the ECU is locked. 0x00 by default, setting it to 0xFF will allow to read the whole ECU including bootzone over KWP2000&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32 kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - INT_RAM [15872]&lt;br /&gt;
* 0xFD00 - INT_RAM_BIT [256]&lt;br /&gt;
* 0xFF800 - RAM [2048]&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET (within RAM)&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block for CCP within bootloader 2&lt;br /&gt;
* 0x3000000 - FLASH_DR [65520]&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[Chassis identifiers|Chassis identifier]]&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;br /&gt;
[[index.php?title=Category:Siemens L4 2.0L]]&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=962</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=962"/>
		<updated>2025-11-19T11:49:23Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
[[File:Kia crossflash prog.png|thumb|[[File:Kia crossflash cal.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash gui.png|thumb]]]]&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
Once the version details have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
Please note: &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car &#039;&#039;is not equipped&#039;&#039; with immobilizer hardware&#039;&#039;&#039; (an immobilizer coil and keys containing a PCF793 transponder) then you&#039;ll be unable to programme the immobiliser data into the ECU. In this scenerio, you won&#039;t be able to start the car or re-program the ECU. The only option is to remove the ECU from the vehicle and bench flash via BSL. To avoid this scenerio, only load ECU firmware appropriate for your region where the immobiliser is preconfigured.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car &#039;&#039;is equipped&#039;&#039; with immobilizer hardware&#039;&#039;&#039; you may need to re-program the immobilizer by running through the Teach Keys procedure (if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;). Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the 0x22 error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=961</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=961"/>
		<updated>2025-11-19T11:47:21Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
[[File:Kia crossflash prog.png|thumb|[[File:Kia crossflash cal.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash gui.png|thumb]]]]&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
Once the version details have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
Please note: &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car &#039;&#039;is not equipped&#039;&#039; with immobilizer hardware&#039;&#039;&#039; (an immobilizer coil and keys containing a PCF793 transponder) then you&#039;ll be unable to programme the immobiliser data into the ECU. In this scenerio, you won&#039;t be able to start the car or re-program the ECU. The only option is to remove the ECU from the vehicle and bench flash via BSL. To avoid this scenerio, only load ECU firmware appropriate for your region where the immobiliser is preconfigured.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car &#039;&#039;is equipped&#039;&#039; with immobilizer hardware&#039;&#039;&#039; you may need to re-program the immobilizer by running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;. Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the 0x22 error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=960</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=960"/>
		<updated>2025-11-19T11:47:01Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
[[File:Kia crossflash prog.png|thumb|[[File:Kia crossflash cal.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash gui.png|thumb]]]]&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
Once the version details have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
Please note: &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car &#039;&#039;is not equipped&#039;&#039; with immobilizer hardware&#039;&#039;&#039; (an immobilizer coil and keys containing a PCF793 transponder) then you&#039;ll be unable to programme the immobiliser data into the ECU. In this scenerio, you won&#039;t be able to start the car or re-program the ECU. The only option here is to remove the ECU from the vehicle and bench flash via BSL. To avoid this scenerio, only load ECU firmware appropriate for your region where the immobiliser is preconfigured.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car &#039;&#039;is equipped&#039;&#039; with immobilizer hardware&#039;&#039;&#039; you may need to re-program the immobilizer by running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;. Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the 0x22 error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=959</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=959"/>
		<updated>2025-11-19T11:46:27Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
[[File:Kia crossflash prog.png|thumb|[[File:Kia crossflash cal.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash gui.png|thumb]]]]&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
Once the version details have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
Please note: &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car &#039;&#039;is not equipped&#039;&#039; with immobilizer hardware&#039;&#039;&#039; (an immobilizer coil and keys containing a PCF793 transponder) then you&#039;ll be unable to programme the immobiliser data into the ECU. In this scenerio, you won&#039;t be able to start the car or re-program the ECU. The only option is to remove the ECU from the vehicle and bench flash via BSL. To avoid this scenerio, only load ECU firmware appropriate for your region where the immobiliser is preconfigured.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car &#039;&#039;is equipped&#039;&#039; with immobilizer hardware&#039;&#039;&#039; you may need to re-program the immobilizer by running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;. Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the 0x22 error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=958</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=958"/>
		<updated>2025-11-19T11:45:22Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
[[File:Kia crossflash prog.png|thumb|[[File:Kia crossflash cal.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash gui.png|thumb]]]]&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
Once the version details have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
Please note: &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car is not equipped with immobilizer hardware&#039;&#039;&#039; (an immobilizer coil and keys containing a PCF793 transponder) then you&#039;ll be unable to programme the immobiliser data into the ECU. In this scenerio, you won&#039;t be able to start the car or re-program the ECU. The only option is to remove the ECU from the vehicle and bench flash via BSL. To avoid this scenerio, only load ECU firmware appropriate for your region where the immobiliser is preconfigured.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car is equipped with immobilizer hardware&#039;&#039;&#039; you may need to re-program the immobilizer by running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;. Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the 0x22 error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=957</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=957"/>
		<updated>2025-11-19T11:44:39Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
[[File:Kia crossflash prog.png|thumb|[[File:Kia crossflash cal.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash gui.png|thumb]]]]&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
Once the version details have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
Please note: &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car is not equipped with immobilizer hardware&#039;&#039;&#039; (an immobilizer coil and keys containing a PCF793 transponder) then you&#039;ll be unable to programme the immobiliser data into the ECU. In this scenerio, you won&#039;t be able to start the car or re-programme the ECU. The only option is to remove the ECU from the vehicle and bench flash via BSL. To avoid this scenerio, only load ECU firmware appropriate for your region where the immobiliser is preconfigured.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car is equipped with immobilizer hardware&#039;&#039;&#039; you may need to re-program the immobilizer by running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;. Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the 0x22 error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=956</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=956"/>
		<updated>2025-11-19T11:43:43Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
[[File:Kia crossflash prog.png|thumb|[[File:Kia crossflash cal.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash gui.png|thumb]]]]&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
Once the version details have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please note:&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car is not equipped with immobilizer hardware&#039;&#039;&#039; (an immobilizer coil and keys containing a PCF793 transponder) then you&#039;ll be unable to programme the immobiliser data into the ECU. In this scenerio, you won&#039;t be able to start the car or re-programme the ECU. The only option is to remove the ECU from the vehicle and bench flash via BSL. To avoid this scenerio, only load ECU firmware appropriate for your region where the immobiliser is preconfigured.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If your car is equipped with immobilizer hardware&#039;&#039;&#039; you may need to re-program the immobilizer by running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;. Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the 0x22 error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=955</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=955"/>
		<updated>2025-11-19T11:30:07Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
[[File:Kia crossflash cal.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash prog.png|thumb]]&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
Once the version detials have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
You may need to re-program the Immobilizer running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;&lt;br /&gt;
&lt;br /&gt;
Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please note:&#039;&#039;&#039; If your car doesn&#039;t have immobilizer hardware (an immobilizer coil and keys containing a PCF793 transponder) then you&#039;ll be unable to programme the immobiliser data into the ECU. In this scenerio, you won&#039;t be able to start the car and the only option is to remove the ECU from the vehicle and bench flash via BSL.&lt;br /&gt;
&lt;br /&gt;
To avoid this scenerio, only load ECU firmware appropriate for your region where the immobiliser is preconfigured.&lt;br /&gt;
[[File:Kia crossflash gui.png|thumb]]&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=668</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=668"/>
		<updated>2025-03-26T20:10:38Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* SIMK43 - 4mbit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
&lt;br /&gt;
=== Memory offset &amp;amp; bin offset ===&lt;br /&gt;
Through OpenGK wiki and projects, you&#039;ll often find the terms memory offset, and bin offset. &lt;br /&gt;
&lt;br /&gt;
You might notice that memory offset is usually around 0x80000 larger than bin offset when referring to the same spot (such as the calibration zone). &lt;br /&gt;
&lt;br /&gt;
Bin offset is referring to the position in your .bin file - and the EEPROM. Memory offset is referring to the CPU offset - such as when reading using ReadMemoryByAddress. &lt;br /&gt;
&lt;br /&gt;
This is because of the c166 memory layout and DPP (Data Page Pointer) configuration. In general, on every c166 project, the memory offset will be at least 0x80000 higher than the bin offset - further description needed.  &lt;br /&gt;
&lt;br /&gt;
=== Regions ===&lt;br /&gt;
Both units memory can be separated into 5 regions:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
All provided offsets are in hex&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!Memory start&lt;br /&gt;
!Memory end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Bin end&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; |0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; |3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E7FF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |E7FF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |XRAM&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |2 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |EF00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |EF00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |CAN1&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |256 bytes&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F200&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F000&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F200&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |ESFR&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |512 bytes&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F600&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FBFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |F600&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FBFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |Internal RAM&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |1.5 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FC00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FC00&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |Internal SFRs&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; |1 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FD00&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FF55?&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FD00&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |FF55?&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |INT_RAM_BIT&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; |256 bytes&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; |88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; |97FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; |90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; |AFFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; |A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; |11FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 50000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 5FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|87FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key verification enabled flag]]&lt;br /&gt;
|0x3E00&lt;br /&gt;
|1&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=00}}&lt;br /&gt;
|Flag determining whether the ECU should ask for KWP authorization key. 0x00 - security access verification enabled, 0xFF - disabled&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|-&lt;br /&gt;
|ECU lock status flag&lt;br /&gt;
|1&lt;br /&gt;
|{{HexConverter|hex=0x00|default-display=hex}}&lt;br /&gt;
|Flag determining whether the ECU is locked. 0x00 by default, setting it to 0xFF will allow to read the whole ECU including bootzone over KWP2000&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32 kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - INT_RAM [15872]&lt;br /&gt;
* 0xFD00 - INT_RAM_BIT [256]&lt;br /&gt;
* 0xFF800 - RAM [2048]&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET (within RAM)&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block for CCP within bootloader 2&lt;br /&gt;
* 0x3000000 - FLASH_DR [65520]&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=K-Line&amp;diff=661</id>
		<title>K-Line</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=K-Line&amp;diff=661"/>
		<updated>2025-03-18T10:44:54Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Input-Output local identifiers */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;K-Line on SIMK43 runs at 10400 baud and uses the KWP2000 protocol for diagnostic communication. &lt;br /&gt;
&lt;br /&gt;
== Connection points ==&lt;br /&gt;
&lt;br /&gt;
=== OBD2 ===&lt;br /&gt;
K-line uses the standard pin 7 on the [[Data link connector (OBD2)|OBD2 connector]]&lt;br /&gt;
&lt;br /&gt;
=== ECU ===&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 without immobilizer installed: ====&lt;br /&gt;
Good news! Your K-Line pins (OBD2/MCC) are connected directly to the K-line pin on the ECU (2.0 - 77)&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 with immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). &#039;&#039;&#039;THERE IS NOTHING CONNECTED TO K-LINE PIN AT THE ECU!!&#039;&#039;&#039; (2.0 77). Instead, all K-line stuff is connected to the ECU&#039;s W-Line (2.0 - 47)&lt;br /&gt;
&lt;br /&gt;
==== If you have 2.7 with or without immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). Your K/Immo-Line pin at the ECU (C133-1, pin 3) is connected to BCM&#039;s &amp;quot;Immo W-line&amp;quot; (BCM-IM, pin 20). 2.7 ECUs don&#039;t have a separate K and W line - it&#039;s all integrated in one pin, you don&#039;t have nothing to worry about.&lt;br /&gt;
&lt;br /&gt;
== KWP2000 ==&lt;br /&gt;
Recommended document: [https://opengk.org/files/Users/dante383/OBDII%20Specifications%20-%20KWP2000%20DaimlerChrysler%202002.pdf OBDII Specifications - KWP2000 DaimlerChrysler 2002.pdf]&lt;br /&gt;
&lt;br /&gt;
To start communication, you need to use Fast Init - so bring the K-line down for exactly 25ms, then up for 25ms followed by StartCommunication request. Python example of that using a FTDI cable [https://github.com/Dante383/gkbus/blob/a3ff894e8352ef2faab36e22553da7ddf5688cb8/gkbus/interface/kline/KLineSerial.py#L48 can be found in GKBus] code.&lt;br /&gt;
&lt;br /&gt;
ID of the ECU is 0x11, and as a diagnostic device you should be using ID 0xF1. So an example command and response would look like this:&lt;br /&gt;
&lt;br /&gt;
Diagnostic device: &amp;lt;code&amp;gt;82 11 F1 27 01 AC&amp;lt;/code&amp;gt; (security access request)&lt;br /&gt;
&lt;br /&gt;
ECU response: &amp;lt;code&amp;gt;83 F1 11 67 02 34 22&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Baudrate ====&lt;br /&gt;
&lt;br /&gt;
By default, SIMK43 uses 10400 baud. On some ECUs (so far testing revealed that &amp;lt;2005 ECUs might not support that), baudrate can be manipulated by additional undocumented parameter of the StartDiagnosticSession service:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Baudrate identifier, &lt;br /&gt;
passed to StartDiagnosticSession&lt;br /&gt;
!Baudrate on K-line &lt;br /&gt;
(bits per second)&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|10400&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|20000&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|40000&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|60000&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|120000&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
 &amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Challenge-response calculation ====&lt;br /&gt;
SIMK43/41 uses a 2 byte seed and 2 byte key for security access. You can take a look at it&#039;s Python implementation in GKFlasher: https://github.com/Dante383/GKFlasher/blob/15a715b18f2119d697a5ceed00f6383f690c4a23/ecu.py#L42&lt;br /&gt;
&lt;br /&gt;
The algorithm presents as so (Python):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;def calculate_key (seed):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    key = 0x9360&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;   &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    for index in range(0x24):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;        key = key * 2 ^ seed&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;       &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    return key &amp;amp; 0xFFFF&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Input-Output local identifiers ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x10&lt;br /&gt;
|check engine light&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x11&lt;br /&gt;
|EVAP canister close valve (on)&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|fuel pump relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|a/c compressor relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|fuel pump control&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x15&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|Canister Close Valve-Lock&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|cooling fan relay high&lt;br /&gt;
|-&lt;br /&gt;
|0x1B&lt;br /&gt;
|cooling fan relay low&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1C&lt;br /&gt;
|main relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|canister purge valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x23&lt;br /&gt;
|idle speed actuator&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x24&lt;br /&gt;
|cvvt valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x30&lt;br /&gt;
|fuel cut-4 cylinders&lt;br /&gt;
|i4 non-cvvt only&lt;br /&gt;
|-&lt;br /&gt;
|0x31&lt;br /&gt;
|ignition coil #1, 4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x32&lt;br /&gt;
|ignition coil #2, 3&lt;br /&gt;
|Coil #5 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x33&lt;br /&gt;
|ignition coil #3, 6&lt;br /&gt;
|Coil #6 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x39&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3A&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3B&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3C&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300701&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300702&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300704&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300708&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300710&lt;br /&gt;
|injector cylinder 5&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300720&lt;br /&gt;
|injector cylinder 6&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x40&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Automatic Transaxle (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x41&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Traction Control System (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x42&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x50&lt;br /&gt;
|adaptive values&lt;br /&gt;
|0x04 - clear function&lt;br /&gt;
|-&lt;br /&gt;
|0x71&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x72&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x73&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x74&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x79&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x7A&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x95&lt;br /&gt;
|evap leakage test&lt;br /&gt;
|0x06 - start function&lt;br /&gt;
|-&lt;br /&gt;
|0x96&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0xA0&lt;br /&gt;
|?&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Routines by local identifier ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x00&lt;br /&gt;
|erase program section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|erase calibration section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|verify and mark blocks as ready to execute&lt;br /&gt;
|Needs to be called after flashing&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|unknown&lt;br /&gt;
|requires security access, returned 0x33 0xE0 on a bench ecu&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|query immobilizer info  &lt;br /&gt;
|1 byte number of keys learnt, 1 bytes immo status (0x01 = learnt), 1 byte key status (0x00 not learnt), 1 byte smartra status if applicable&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|needs to be called before immobilizer password teaching/changing  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|needs to be called before immobilizer teaching. &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x15&lt;br /&gt;
|needs to be called before ECU immobilizer reset  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|needs to be called before putting immobilizer in limp home mode  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x17&lt;br /&gt;
|input new limp home password  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x18&lt;br /&gt;
|activate limp home mode  &lt;br /&gt;
|takes user-provided (default: 2345) password as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x19&lt;br /&gt;
|confirm limp home password change &lt;br /&gt;
|takes 0x01 as a parameter &lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|input 6 digit immobilizer password   &lt;br /&gt;
|Needs to be called before teaching, resetting or other actions modifying the immo system. Takes password and 6x 0xFF as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x1B, 0x1C, 0x1D, 0x1E&lt;br /&gt;
|teach keys 1,2,3,4  &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|reset ECU immo.   &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x25&lt;br /&gt;
|needs to be called before neutralizing smartra  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x26&lt;br /&gt;
|confirm neutralizing smartra.&lt;br /&gt;
|takes 0x01 as a parameter&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=K-Line&amp;diff=660</id>
		<title>K-Line</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=K-Line&amp;diff=660"/>
		<updated>2025-03-18T10:34:43Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Input-Output local identifiers */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;K-Line on SIMK43 runs at 10400 baud and uses the KWP2000 protocol for diagnostic communication. &lt;br /&gt;
&lt;br /&gt;
== Connection points ==&lt;br /&gt;
&lt;br /&gt;
=== OBD2 ===&lt;br /&gt;
K-line uses the standard pin 7 on the [[Data link connector (OBD2)|OBD2 connector]]&lt;br /&gt;
&lt;br /&gt;
=== ECU ===&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 without immobilizer installed: ====&lt;br /&gt;
Good news! Your K-Line pins (OBD2/MCC) are connected directly to the K-line pin on the ECU (2.0 - 77)&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 with immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). &#039;&#039;&#039;THERE IS NOTHING CONNECTED TO K-LINE PIN AT THE ECU!!&#039;&#039;&#039; (2.0 77). Instead, all K-line stuff is connected to the ECU&#039;s W-Line (2.0 - 47)&lt;br /&gt;
&lt;br /&gt;
==== If you have 2.7 with or without immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). Your K/Immo-Line pin at the ECU (C133-1, pin 3) is connected to BCM&#039;s &amp;quot;Immo W-line&amp;quot; (BCM-IM, pin 20). 2.7 ECUs don&#039;t have a separate K and W line - it&#039;s all integrated in one pin, you don&#039;t have nothing to worry about.&lt;br /&gt;
&lt;br /&gt;
== KWP2000 ==&lt;br /&gt;
Recommended document: [https://opengk.org/files/Users/dante383/OBDII%20Specifications%20-%20KWP2000%20DaimlerChrysler%202002.pdf OBDII Specifications - KWP2000 DaimlerChrysler 2002.pdf]&lt;br /&gt;
&lt;br /&gt;
To start communication, you need to use Fast Init - so bring the K-line down for exactly 25ms, then up for 25ms followed by StartCommunication request. Python example of that using a FTDI cable [https://github.com/Dante383/gkbus/blob/a3ff894e8352ef2faab36e22553da7ddf5688cb8/gkbus/interface/kline/KLineSerial.py#L48 can be found in GKBus] code.&lt;br /&gt;
&lt;br /&gt;
ID of the ECU is 0x11, and as a diagnostic device you should be using ID 0xF1. So an example command and response would look like this:&lt;br /&gt;
&lt;br /&gt;
Diagnostic device: &amp;lt;code&amp;gt;82 11 F1 27 01 AC&amp;lt;/code&amp;gt; (security access request)&lt;br /&gt;
&lt;br /&gt;
ECU response: &amp;lt;code&amp;gt;83 F1 11 67 02 34 22&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Baudrate ====&lt;br /&gt;
&lt;br /&gt;
By default, SIMK43 uses 10400 baud. On some ECUs (so far testing revealed that &amp;lt;2005 ECUs might not support that), baudrate can be manipulated by additional undocumented parameter of the StartDiagnosticSession service:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Baudrate identifier, &lt;br /&gt;
passed to StartDiagnosticSession&lt;br /&gt;
!Baudrate on K-line &lt;br /&gt;
(bits per second)&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|10400&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|20000&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|40000&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|60000&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|120000&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
 &amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Challenge-response calculation ====&lt;br /&gt;
SIMK43/41 uses a 2 byte seed and 2 byte key for security access. You can take a look at it&#039;s Python implementation in GKFlasher: https://github.com/Dante383/GKFlasher/blob/15a715b18f2119d697a5ceed00f6383f690c4a23/ecu.py#L42&lt;br /&gt;
&lt;br /&gt;
The algorithm presents as so (Python):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;def calculate_key (seed):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    key = 0x9360&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;   &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    for index in range(0x24):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;        key = key * 2 ^ seed&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;       &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    return key &amp;amp; 0xFFFF&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Input-Output local identifiers ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x10&lt;br /&gt;
|check engine light&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x11&lt;br /&gt;
|EVAP canister close valve (on)&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|fuel pump relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|a/c compressor relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|fuel pump control&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|Canister Close Valve-Lock&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|cooling fan relay high&lt;br /&gt;
|-&lt;br /&gt;
|0x1B&lt;br /&gt;
|cooling fan relay low&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1C&lt;br /&gt;
|main relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|canister purge valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x23&lt;br /&gt;
|idle speed actuator&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x24&lt;br /&gt;
|cvvt valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x30&lt;br /&gt;
|fuel cut-4 cylinders&lt;br /&gt;
|i4 non-cvvt only&lt;br /&gt;
|-&lt;br /&gt;
|0x31&lt;br /&gt;
|ignition coil #1, 4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x32&lt;br /&gt;
|ignition coil #2, 3&lt;br /&gt;
|Coil #5 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x33&lt;br /&gt;
|ignition coil #3, 6&lt;br /&gt;
|Coil #6 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x39&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3A&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3B&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3C&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300701&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300702&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300704&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300708&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300710&lt;br /&gt;
|injector cylinder 5&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300720&lt;br /&gt;
|injector cylinder 6&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x40&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Automatic Transaxle (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x41&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Traction Control System (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x50&lt;br /&gt;
|adaptive values&lt;br /&gt;
|0x04 - clear function&lt;br /&gt;
|-&lt;br /&gt;
|0x95&lt;br /&gt;
|evap leakage test&lt;br /&gt;
|0x06 - start function&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Routines by local identifier ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x00&lt;br /&gt;
|erase program section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|erase calibration section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|verify and mark blocks as ready to execute&lt;br /&gt;
|Needs to be called after flashing&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|unknown&lt;br /&gt;
|requires security access, returned 0x33 0xE0 on a bench ecu&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|query immobilizer info  &lt;br /&gt;
|1 byte number of keys learnt, 1 bytes immo status (0x01 = learnt), 1 byte key status (0x00 not learnt), 1 byte smartra status if applicable&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|needs to be called before immobilizer password teaching/changing  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|needs to be called before immobilizer teaching. &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x15&lt;br /&gt;
|needs to be called before ECU immobilizer reset  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|needs to be called before putting immobilizer in limp home mode  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x17&lt;br /&gt;
|input new limp home password  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x18&lt;br /&gt;
|activate limp home mode  &lt;br /&gt;
|takes user-provided (default: 2345) password as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x19&lt;br /&gt;
|confirm limp home password change &lt;br /&gt;
|takes 0x01 as a parameter &lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|input 6 digit immobilizer password   &lt;br /&gt;
|Needs to be called before teaching, resetting or other actions modifying the immo system. Takes password and 6x 0xFF as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x1B, 0x1C, 0x1D, 0x1E&lt;br /&gt;
|teach keys 1,2,3,4  &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|reset ECU immo.   &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x25&lt;br /&gt;
|needs to be called before neutralizing smartra  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x26&lt;br /&gt;
|confirm neutralizing smartra.&lt;br /&gt;
|takes 0x01 as a parameter&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=K-Line&amp;diff=659</id>
		<title>K-Line</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=K-Line&amp;diff=659"/>
		<updated>2025-03-17T19:14:35Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Input-Output local identifiers */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;K-Line on SIMK43 runs at 10400 baud and uses the KWP2000 protocol for diagnostic communication. &lt;br /&gt;
&lt;br /&gt;
== Connection points ==&lt;br /&gt;
&lt;br /&gt;
=== OBD2 ===&lt;br /&gt;
K-line uses the standard pin 7 on the [[Data link connector (OBD2)|OBD2 connector]]&lt;br /&gt;
&lt;br /&gt;
=== ECU ===&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 without immobilizer installed: ====&lt;br /&gt;
Good news! Your K-Line pins (OBD2/MCC) are connected directly to the K-line pin on the ECU (2.0 - 77)&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 with immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). &#039;&#039;&#039;THERE IS NOTHING CONNECTED TO K-LINE PIN AT THE ECU!!&#039;&#039;&#039; (2.0 77). Instead, all K-line stuff is connected to the ECU&#039;s W-Line (2.0 - 47)&lt;br /&gt;
&lt;br /&gt;
==== If you have 2.7 with or without immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). Your K/Immo-Line pin at the ECU (C133-1, pin 3) is connected to BCM&#039;s &amp;quot;Immo W-line&amp;quot; (BCM-IM, pin 20). 2.7 ECUs don&#039;t have a separate K and W line - it&#039;s all integrated in one pin, you don&#039;t have nothing to worry about.&lt;br /&gt;
&lt;br /&gt;
== KWP2000 ==&lt;br /&gt;
Recommended document: [https://opengk.org/files/Users/dante383/OBDII%20Specifications%20-%20KWP2000%20DaimlerChrysler%202002.pdf OBDII Specifications - KWP2000 DaimlerChrysler 2002.pdf]&lt;br /&gt;
&lt;br /&gt;
To start communication, you need to use Fast Init - so bring the K-line down for exactly 25ms, then up for 25ms followed by StartCommunication request. Python example of that using a FTDI cable [https://github.com/Dante383/gkbus/blob/a3ff894e8352ef2faab36e22553da7ddf5688cb8/gkbus/interface/kline/KLineSerial.py#L48 can be found in GKBus] code.&lt;br /&gt;
&lt;br /&gt;
ID of the ECU is 0x11, and as a diagnostic device you should be using ID 0xF1. So an example command and response would look like this:&lt;br /&gt;
&lt;br /&gt;
Diagnostic device: &amp;lt;code&amp;gt;82 11 F1 27 01 AC&amp;lt;/code&amp;gt; (security access request)&lt;br /&gt;
&lt;br /&gt;
ECU response: &amp;lt;code&amp;gt;83 F1 11 67 02 34 22&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Baudrate ====&lt;br /&gt;
&lt;br /&gt;
By default, SIMK43 uses 10400 baud. On some ECUs (so far testing revealed that &amp;lt;2005 ECUs might not support that), baudrate can be manipulated by additional undocumented parameter of the StartDiagnosticSession service:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Baudrate identifier, &lt;br /&gt;
passed to StartDiagnosticSession&lt;br /&gt;
!Baudrate on K-line &lt;br /&gt;
(bits per second)&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|10400&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|20000&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|40000&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|60000&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|120000&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
 &amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Challenge-response calculation ====&lt;br /&gt;
SIMK43/41 uses a 2 byte seed and 2 byte key for security access. You can take a look at it&#039;s Python implementation in GKFlasher: https://github.com/Dante383/GKFlasher/blob/15a715b18f2119d697a5ceed00f6383f690c4a23/ecu.py#L42&lt;br /&gt;
&lt;br /&gt;
The algorithm presents as so (Python):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;def calculate_key (seed):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    key = 0x9360&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;   &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    for index in range(0x24):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;        key = key * 2 ^ seed&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;       &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    return key &amp;amp; 0xFFFF&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Input-Output local identifiers ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x10&lt;br /&gt;
|check engine light&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x11&lt;br /&gt;
|EVAP canister close valve (on)&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|fuel pump relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|a/c compressor relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|fuel pump control&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|Canister Close Valve-Lock&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|cooling fan relay high&lt;br /&gt;
|-&lt;br /&gt;
|0x1B&lt;br /&gt;
|cooling fan relay low&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1C&lt;br /&gt;
|main relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|canister purge valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x23&lt;br /&gt;
|idle speed actuator&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x24&lt;br /&gt;
|cvvt valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x31&lt;br /&gt;
|ignition coil #1, 4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x32&lt;br /&gt;
|ignition coil #2, 3&lt;br /&gt;
|Coil #5 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x33&lt;br /&gt;
|ignition coil #3, 6&lt;br /&gt;
|Coil #6 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x39&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3A&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3B&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3C&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300701&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300702&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300704&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300708&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300710&lt;br /&gt;
|injector cylinder 5&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300720&lt;br /&gt;
|injector cylinder 6&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x41&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Automatic Transaxle (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x42&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Traction Control System (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x50&lt;br /&gt;
|adaptive values&lt;br /&gt;
|0x04 - clear function&lt;br /&gt;
|-&lt;br /&gt;
|0x95&lt;br /&gt;
|evap leakage test&lt;br /&gt;
|0x06 - start function&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Routines by local identifier ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x00&lt;br /&gt;
|erase program section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|erase calibration section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|verify and mark blocks as ready to execute&lt;br /&gt;
|Needs to be called after flashing&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|unknown&lt;br /&gt;
|requires security access, returned 0x33 0xE0 on a bench ecu&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|query immobilizer info  &lt;br /&gt;
|1 byte number of keys learnt, 1 bytes immo status (0x01 = learnt), 1 byte key status (0x00 not learnt), 1 byte smartra status if applicable&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|needs to be called before immobilizer password teaching/changing  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|needs to be called before immobilizer teaching. &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x15&lt;br /&gt;
|needs to be called before ECU immobilizer reset  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|needs to be called before putting immobilizer in limp home mode  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x17&lt;br /&gt;
|input new limp home password  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x18&lt;br /&gt;
|activate limp home mode  &lt;br /&gt;
|takes user-provided (default: 2345) password as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x19&lt;br /&gt;
|confirm limp home password change &lt;br /&gt;
|takes 0x01 as a parameter &lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|input 6 digit immobilizer password   &lt;br /&gt;
|Needs to be called before teaching, resetting or other actions modifying the immo system. Takes password and 6x 0xFF as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x1B, 0x1C, 0x1D, 0x1E&lt;br /&gt;
|teach keys 1,2,3,4  &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|reset ECU immo.   &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x25&lt;br /&gt;
|needs to be called before neutralizing smartra  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x26&lt;br /&gt;
|confirm neutralizing smartra.&lt;br /&gt;
|takes 0x01 as a parameter&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=K-Line&amp;diff=658</id>
		<title>K-Line</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=K-Line&amp;diff=658"/>
		<updated>2025-03-17T19:14:05Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Input-Output local identifiers */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;K-Line on SIMK43 runs at 10400 baud and uses the KWP2000 protocol for diagnostic communication. &lt;br /&gt;
&lt;br /&gt;
== Connection points ==&lt;br /&gt;
&lt;br /&gt;
=== OBD2 ===&lt;br /&gt;
K-line uses the standard pin 7 on the [[Data link connector (OBD2)|OBD2 connector]]&lt;br /&gt;
&lt;br /&gt;
=== ECU ===&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 without immobilizer installed: ====&lt;br /&gt;
Good news! Your K-Line pins (OBD2/MCC) are connected directly to the K-line pin on the ECU (2.0 - 77)&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 with immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). &#039;&#039;&#039;THERE IS NOTHING CONNECTED TO K-LINE PIN AT THE ECU!!&#039;&#039;&#039; (2.0 77). Instead, all K-line stuff is connected to the ECU&#039;s W-Line (2.0 - 47)&lt;br /&gt;
&lt;br /&gt;
==== If you have 2.7 with or without immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). Your K/Immo-Line pin at the ECU (C133-1, pin 3) is connected to BCM&#039;s &amp;quot;Immo W-line&amp;quot; (BCM-IM, pin 20). 2.7 ECUs don&#039;t have a separate K and W line - it&#039;s all integrated in one pin, you don&#039;t have nothing to worry about.&lt;br /&gt;
&lt;br /&gt;
== KWP2000 ==&lt;br /&gt;
Recommended document: [https://opengk.org/files/Users/dante383/OBDII%20Specifications%20-%20KWP2000%20DaimlerChrysler%202002.pdf OBDII Specifications - KWP2000 DaimlerChrysler 2002.pdf]&lt;br /&gt;
&lt;br /&gt;
To start communication, you need to use Fast Init - so bring the K-line down for exactly 25ms, then up for 25ms followed by StartCommunication request. Python example of that using a FTDI cable [https://github.com/Dante383/gkbus/blob/a3ff894e8352ef2faab36e22553da7ddf5688cb8/gkbus/interface/kline/KLineSerial.py#L48 can be found in GKBus] code.&lt;br /&gt;
&lt;br /&gt;
ID of the ECU is 0x11, and as a diagnostic device you should be using ID 0xF1. So an example command and response would look like this:&lt;br /&gt;
&lt;br /&gt;
Diagnostic device: &amp;lt;code&amp;gt;82 11 F1 27 01 AC&amp;lt;/code&amp;gt; (security access request)&lt;br /&gt;
&lt;br /&gt;
ECU response: &amp;lt;code&amp;gt;83 F1 11 67 02 34 22&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Baudrate ====&lt;br /&gt;
&lt;br /&gt;
By default, SIMK43 uses 10400 baud. On some ECUs (so far testing revealed that &amp;lt;2005 ECUs might not support that), baudrate can be manipulated by additional undocumented parameter of the StartDiagnosticSession service:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Baudrate identifier, &lt;br /&gt;
passed to StartDiagnosticSession&lt;br /&gt;
!Baudrate on K-line &lt;br /&gt;
(bits per second)&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|10400&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|20000&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|40000&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|60000&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|120000&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
 &amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Challenge-response calculation ====&lt;br /&gt;
SIMK43/41 uses a 2 byte seed and 2 byte key for security access. You can take a look at it&#039;s Python implementation in GKFlasher: https://github.com/Dante383/GKFlasher/blob/15a715b18f2119d697a5ceed00f6383f690c4a23/ecu.py#L42&lt;br /&gt;
&lt;br /&gt;
The algorithm presents as so (Python):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;def calculate_key (seed):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    key = 0x9360&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;   &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    for index in range(0x24):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;        key = key * 2 ^ seed&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;       &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    return key &amp;amp; 0xFFFF&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Input-Output local identifiers ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x10&lt;br /&gt;
|check engine light&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x11&lt;br /&gt;
|EVAP canister close valve (on)&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|fuel pump relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|a/c compressor relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|fuel pump control&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|Canister Close Valve-Closed&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|cooling fan relay high&lt;br /&gt;
|-&lt;br /&gt;
|0x1B&lt;br /&gt;
|cooling fan relay low&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1C&lt;br /&gt;
|main relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|canister purge valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x23&lt;br /&gt;
|idle speed actuator&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x24&lt;br /&gt;
|cvvt valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x31&lt;br /&gt;
|ignition coil #1, 4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x32&lt;br /&gt;
|ignition coil #2, 3&lt;br /&gt;
|Coil #5 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x33&lt;br /&gt;
|ignition coil #3, 6&lt;br /&gt;
|Coil #6 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x39&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3A&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3B&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3C&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300701&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300702&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300704&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300708&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300710&lt;br /&gt;
|injector cylinder 5&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300720&lt;br /&gt;
|injector cylinder 6&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x41&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Automatic Transaxle (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x42&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Traction Control System (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x50&lt;br /&gt;
|adaptive values&lt;br /&gt;
|0x04 - clear function&lt;br /&gt;
|-&lt;br /&gt;
|0x95&lt;br /&gt;
|evap leakage test&lt;br /&gt;
|0x06 - start function&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Routines by local identifier ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x00&lt;br /&gt;
|erase program section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|erase calibration section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|verify and mark blocks as ready to execute&lt;br /&gt;
|Needs to be called after flashing&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|unknown&lt;br /&gt;
|requires security access, returned 0x33 0xE0 on a bench ecu&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|query immobilizer info  &lt;br /&gt;
|1 byte number of keys learnt, 1 bytes immo status (0x01 = learnt), 1 byte key status (0x00 not learnt), 1 byte smartra status if applicable&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|needs to be called before immobilizer password teaching/changing  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|needs to be called before immobilizer teaching. &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x15&lt;br /&gt;
|needs to be called before ECU immobilizer reset  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|needs to be called before putting immobilizer in limp home mode  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x17&lt;br /&gt;
|input new limp home password  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x18&lt;br /&gt;
|activate limp home mode  &lt;br /&gt;
|takes user-provided (default: 2345) password as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x19&lt;br /&gt;
|confirm limp home password change &lt;br /&gt;
|takes 0x01 as a parameter &lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|input 6 digit immobilizer password   &lt;br /&gt;
|Needs to be called before teaching, resetting or other actions modifying the immo system. Takes password and 6x 0xFF as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x1B, 0x1C, 0x1D, 0x1E&lt;br /&gt;
|teach keys 1,2,3,4  &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|reset ECU immo.   &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x25&lt;br /&gt;
|needs to be called before neutralizing smartra  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x26&lt;br /&gt;
|confirm neutralizing smartra.&lt;br /&gt;
|takes 0x01 as a parameter&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=K-Line&amp;diff=657</id>
		<title>K-Line</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=K-Line&amp;diff=657"/>
		<updated>2025-03-17T19:13:00Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Input-Output local identifiers */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;K-Line on SIMK43 runs at 10400 baud and uses the KWP2000 protocol for diagnostic communication. &lt;br /&gt;
&lt;br /&gt;
== Connection points ==&lt;br /&gt;
&lt;br /&gt;
=== OBD2 ===&lt;br /&gt;
K-line uses the standard pin 7 on the [[Data link connector (OBD2)|OBD2 connector]]&lt;br /&gt;
&lt;br /&gt;
=== ECU ===&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 without immobilizer installed: ====&lt;br /&gt;
Good news! Your K-Line pins (OBD2/MCC) are connected directly to the K-line pin on the ECU (2.0 - 77)&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 with immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). &#039;&#039;&#039;THERE IS NOTHING CONNECTED TO K-LINE PIN AT THE ECU!!&#039;&#039;&#039; (2.0 77). Instead, all K-line stuff is connected to the ECU&#039;s W-Line (2.0 - 47)&lt;br /&gt;
&lt;br /&gt;
==== If you have 2.7 with or without immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). Your K/Immo-Line pin at the ECU (C133-1, pin 3) is connected to BCM&#039;s &amp;quot;Immo W-line&amp;quot; (BCM-IM, pin 20). 2.7 ECUs don&#039;t have a separate K and W line - it&#039;s all integrated in one pin, you don&#039;t have nothing to worry about.&lt;br /&gt;
&lt;br /&gt;
== KWP2000 ==&lt;br /&gt;
Recommended document: [https://opengk.org/files/Users/dante383/OBDII%20Specifications%20-%20KWP2000%20DaimlerChrysler%202002.pdf OBDII Specifications - KWP2000 DaimlerChrysler 2002.pdf]&lt;br /&gt;
&lt;br /&gt;
To start communication, you need to use Fast Init - so bring the K-line down for exactly 25ms, then up for 25ms followed by StartCommunication request. Python example of that using a FTDI cable [https://github.com/Dante383/gkbus/blob/a3ff894e8352ef2faab36e22553da7ddf5688cb8/gkbus/interface/kline/KLineSerial.py#L48 can be found in GKBus] code.&lt;br /&gt;
&lt;br /&gt;
ID of the ECU is 0x11, and as a diagnostic device you should be using ID 0xF1. So an example command and response would look like this:&lt;br /&gt;
&lt;br /&gt;
Diagnostic device: &amp;lt;code&amp;gt;82 11 F1 27 01 AC&amp;lt;/code&amp;gt; (security access request)&lt;br /&gt;
&lt;br /&gt;
ECU response: &amp;lt;code&amp;gt;83 F1 11 67 02 34 22&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Baudrate ====&lt;br /&gt;
&lt;br /&gt;
By default, SIMK43 uses 10400 baud. On some ECUs (so far testing revealed that &amp;lt;2005 ECUs might not support that), baudrate can be manipulated by additional undocumented parameter of the StartDiagnosticSession service:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Baudrate identifier, &lt;br /&gt;
passed to StartDiagnosticSession&lt;br /&gt;
!Baudrate on K-line &lt;br /&gt;
(bits per second)&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|10400&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|20000&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|40000&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|60000&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|120000&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
 &amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Challenge-response calculation ====&lt;br /&gt;
SIMK43/41 uses a 2 byte seed and 2 byte key for security access. You can take a look at it&#039;s Python implementation in GKFlasher: https://github.com/Dante383/GKFlasher/blob/15a715b18f2119d697a5ceed00f6383f690c4a23/ecu.py#L42&lt;br /&gt;
&lt;br /&gt;
The algorithm presents as so (Python):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;def calculate_key (seed):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    key = 0x9360&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;   &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    for index in range(0x24):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;        key = key * 2 ^ seed&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;       &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    return key &amp;amp; 0xFFFF&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Input-Output local identifiers ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x10&lt;br /&gt;
|check engine light&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x11&lt;br /&gt;
|EVAP canister close valve (on)&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|fuel pump relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|a/c compressor relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|fuel pump control&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|&amp;quot;Canister Close Valve-Clocked&amp;quot; (whatever that means)&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|cooling fan relay high&lt;br /&gt;
|-&lt;br /&gt;
|0x1B&lt;br /&gt;
|cooling fan relay low&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1C&lt;br /&gt;
|main relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|canister purge valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x23&lt;br /&gt;
|idle speed actuator&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x24&lt;br /&gt;
|cvvt valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x31&lt;br /&gt;
|ignition coil #1, 4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x32&lt;br /&gt;
|ignition coil #2, 3&lt;br /&gt;
|Coil #5 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x33&lt;br /&gt;
|ignition coil #3, 6&lt;br /&gt;
|Coil #6 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x39&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3A&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3B&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3C&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300701&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300702&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300704&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300708&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300710&lt;br /&gt;
|injector cylinder 5&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300720&lt;br /&gt;
|injector cylinder 6&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x41&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Automatic Transaxle (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x42&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Traction Control System (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x50&lt;br /&gt;
|adaptive values&lt;br /&gt;
|0x04 - clear function&lt;br /&gt;
|-&lt;br /&gt;
|0x95&lt;br /&gt;
|evap leakage test&lt;br /&gt;
|0x06 - start function&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Routines by local identifier ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x00&lt;br /&gt;
|erase program section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|erase calibration section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|verify and mark blocks as ready to execute&lt;br /&gt;
|Needs to be called after flashing&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|unknown&lt;br /&gt;
|requires security access, returned 0x33 0xE0 on a bench ecu&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|query immobilizer info  &lt;br /&gt;
|1 byte number of keys learnt, 1 bytes immo status (0x01 = learnt), 1 byte key status (0x00 not learnt), 1 byte smartra status if applicable&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|needs to be called before immobilizer password teaching/changing  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|needs to be called before immobilizer teaching. &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x15&lt;br /&gt;
|needs to be called before ECU immobilizer reset  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|needs to be called before putting immobilizer in limp home mode  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x17&lt;br /&gt;
|input new limp home password  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x18&lt;br /&gt;
|activate limp home mode  &lt;br /&gt;
|takes user-provided (default: 2345) password as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x19&lt;br /&gt;
|confirm limp home password change &lt;br /&gt;
|takes 0x01 as a parameter &lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|input 6 digit immobilizer password   &lt;br /&gt;
|Needs to be called before teaching, resetting or other actions modifying the immo system. Takes password and 6x 0xFF as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x1B, 0x1C, 0x1D, 0x1E&lt;br /&gt;
|teach keys 1,2,3,4  &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|reset ECU immo.   &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x25&lt;br /&gt;
|needs to be called before neutralizing smartra  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x26&lt;br /&gt;
|confirm neutralizing smartra.&lt;br /&gt;
|takes 0x01 as a parameter&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=K-Line&amp;diff=656</id>
		<title>K-Line</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=K-Line&amp;diff=656"/>
		<updated>2025-03-17T19:03:12Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Input-Output local identifiers */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;K-Line on SIMK43 runs at 10400 baud and uses the KWP2000 protocol for diagnostic communication. &lt;br /&gt;
&lt;br /&gt;
== Connection points ==&lt;br /&gt;
&lt;br /&gt;
=== OBD2 ===&lt;br /&gt;
K-line uses the standard pin 7 on the [[Data link connector (OBD2)|OBD2 connector]]&lt;br /&gt;
&lt;br /&gt;
=== ECU ===&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 without immobilizer installed: ====&lt;br /&gt;
Good news! Your K-Line pins (OBD2/MCC) are connected directly to the K-line pin on the ECU (2.0 - 77)&lt;br /&gt;
&lt;br /&gt;
==== If you have 1.6 or 2.0 with immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). &#039;&#039;&#039;THERE IS NOTHING CONNECTED TO K-LINE PIN AT THE ECU!!&#039;&#039;&#039; (2.0 77). Instead, all K-line stuff is connected to the ECU&#039;s W-Line (2.0 - 47)&lt;br /&gt;
&lt;br /&gt;
==== If you have 2.7 with or without immobilizer installed: ====&lt;br /&gt;
Your K-Line pins (OBD2/MCC) are connected to BCM&#039;s &amp;quot;Diagnosis&amp;quot; pin (BCM-IM, pin 19). Your K/Immo-Line pin at the ECU (C133-1, pin 3) is connected to BCM&#039;s &amp;quot;Immo W-line&amp;quot; (BCM-IM, pin 20). 2.7 ECUs don&#039;t have a separate K and W line - it&#039;s all integrated in one pin, you don&#039;t have nothing to worry about.&lt;br /&gt;
&lt;br /&gt;
== KWP2000 ==&lt;br /&gt;
Recommended document: [https://opengk.org/files/Users/dante383/OBDII%20Specifications%20-%20KWP2000%20DaimlerChrysler%202002.pdf OBDII Specifications - KWP2000 DaimlerChrysler 2002.pdf]&lt;br /&gt;
&lt;br /&gt;
To start communication, you need to use Fast Init - so bring the K-line down for exactly 25ms, then up for 25ms followed by StartCommunication request. Python example of that using a FTDI cable [https://github.com/Dante383/gkbus/blob/a3ff894e8352ef2faab36e22553da7ddf5688cb8/gkbus/interface/kline/KLineSerial.py#L48 can be found in GKBus] code.&lt;br /&gt;
&lt;br /&gt;
ID of the ECU is 0x11, and as a diagnostic device you should be using ID 0xF1. So an example command and response would look like this:&lt;br /&gt;
&lt;br /&gt;
Diagnostic device: &amp;lt;code&amp;gt;82 11 F1 27 01 AC&amp;lt;/code&amp;gt; (security access request)&lt;br /&gt;
&lt;br /&gt;
ECU response: &amp;lt;code&amp;gt;83 F1 11 67 02 34 22&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Baudrate ====&lt;br /&gt;
&lt;br /&gt;
By default, SIMK43 uses 10400 baud. On some ECUs (so far testing revealed that &amp;lt;2005 ECUs might not support that), baudrate can be manipulated by additional undocumented parameter of the StartDiagnosticSession service:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Baudrate identifier, &lt;br /&gt;
passed to StartDiagnosticSession&lt;br /&gt;
!Baudrate on K-line &lt;br /&gt;
(bits per second)&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|10400&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|20000&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|40000&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|60000&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|120000&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
 &amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Challenge-response calculation ====&lt;br /&gt;
SIMK43/41 uses a 2 byte seed and 2 byte key for security access. You can take a look at it&#039;s Python implementation in GKFlasher: https://github.com/Dante383/GKFlasher/blob/15a715b18f2119d697a5ceed00f6383f690c4a23/ecu.py#L42&lt;br /&gt;
&lt;br /&gt;
The algorithm presents as so (Python):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;def calculate_key (seed):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    key = 0x9360&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;   &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    for index in range(0x24):&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;        key = key * 2 ^ seed&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;       &amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;    return key &amp;amp; 0xFFFF&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Input-Output local identifiers ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x10&lt;br /&gt;
|check engine light&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x11&lt;br /&gt;
|EVAP canister close valve (on)&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|fuel pump relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|a/c compressor relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|fuel pump control&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|&amp;quot;Canister Close Valve-Clocked&amp;quot; (whatever that means)&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|cooling fan relay high&lt;br /&gt;
|-&lt;br /&gt;
|0x1B&lt;br /&gt;
|cooling fan relay low&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x1C&lt;br /&gt;
|main relay&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|canister purge valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x23&lt;br /&gt;
|idle speed actuator&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x24&lt;br /&gt;
|cvvt valve&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x31&lt;br /&gt;
|ignition coil #1, 4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x32&lt;br /&gt;
|ignition coil #2, 3&lt;br /&gt;
|Coil #5 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x33&lt;br /&gt;
|ignition coil #3, 6&lt;br /&gt;
|Coil #6 v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x39&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3A&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3B&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x3C&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|i4 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300701&lt;br /&gt;
|injector cylinder 1&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300702&lt;br /&gt;
|injector cylinder 2&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300704&lt;br /&gt;
|injector cylinder 3&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300708&lt;br /&gt;
|injector cylinder 4&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300710&lt;br /&gt;
|injector cylinder 5&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x300720&lt;br /&gt;
|injector cylinder 6&lt;br /&gt;
|v6 only&lt;br /&gt;
|-&lt;br /&gt;
|0x41&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Automatic Transaxle (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x42&lt;br /&gt;
|Version Configuration&lt;br /&gt;
|Traction Control System (0x08) - This is the ECU reset function to install M/T or Non-TCS system.&lt;br /&gt;
|-&lt;br /&gt;
|0x50&lt;br /&gt;
|adaptive values&lt;br /&gt;
|0x04 - clear function&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Routines by local identifier ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Identifier (hex)&lt;br /&gt;
!Description&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|0x00&lt;br /&gt;
|erase program section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x01&lt;br /&gt;
|erase calibration section&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x02&lt;br /&gt;
|verify and mark blocks as ready to execute&lt;br /&gt;
|Needs to be called after flashing&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x03&lt;br /&gt;
|unknown&lt;br /&gt;
|requires security access, returned 0x33 0xE0 on a bench ecu&lt;br /&gt;
|-&lt;br /&gt;
|0x04&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x05&lt;br /&gt;
|unknown&lt;br /&gt;
|returns 0x22 Conditions Not Correct Or Request Sequence Error&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x12&lt;br /&gt;
|query immobilizer info  &lt;br /&gt;
|1 byte number of keys learnt, 1 bytes immo status (0x01 = learnt), 1 byte key status (0x00 not learnt), 1 byte smartra status if applicable&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x13&lt;br /&gt;
|needs to be called before immobilizer password teaching/changing  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x14&lt;br /&gt;
|needs to be called before immobilizer teaching. &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x15&lt;br /&gt;
|needs to be called before ECU immobilizer reset  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x16&lt;br /&gt;
|needs to be called before putting immobilizer in limp home mode  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x17&lt;br /&gt;
|input new limp home password  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x18&lt;br /&gt;
|activate limp home mode  &lt;br /&gt;
|takes user-provided (default: 2345) password as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x19&lt;br /&gt;
|confirm limp home password change &lt;br /&gt;
|takes 0x01 as a parameter &lt;br /&gt;
|-&lt;br /&gt;
|0x1A&lt;br /&gt;
|input 6 digit immobilizer password   &lt;br /&gt;
|Needs to be called before teaching, resetting or other actions modifying the immo system. Takes password and 6x 0xFF as parameters&lt;br /&gt;
|-&lt;br /&gt;
|0x1B, 0x1C, 0x1D, 0x1E&lt;br /&gt;
|teach keys 1,2,3,4  &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x20&lt;br /&gt;
|reset ECU immo.   &lt;br /&gt;
|Takes 0x01 as a parameter&lt;br /&gt;
|-&lt;br /&gt;
|0x25&lt;br /&gt;
|needs to be called before neutralizing smartra  &lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|0x26&lt;br /&gt;
|confirm neutralizing smartra.&lt;br /&gt;
|takes 0x01 as a parameter&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=GKFlasher_Instructions&amp;diff=633</id>
		<title>GKFlasher Instructions</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=GKFlasher_Instructions&amp;diff=633"/>
		<updated>2025-02-21T12:49:39Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
GKFlasher is an open source Python project supported by OpenGK, written by dante383 and dmg210. This project is a multi OBD2 tool for the Siemens ECUs found on the Hyundai and Kia vehicles. It can read &amp;amp; write tune data, correct EEPROM checksums and clear adaptive values from your ECU. &lt;br /&gt;
&lt;br /&gt;
== MSI Install Package ==&lt;br /&gt;
We have precompiled MSI install packages available from the GitHub releases page:&lt;br /&gt;
&lt;br /&gt;
https://github.com/Dante383/GKFlasher/releases&lt;br /&gt;
&lt;br /&gt;
=== Prerequisites ===&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; First you will need a FTDI USB-OBD2 interface cable. This is often the same cable used on German vehicles. The chipset on the board must be a real FTDI chip and cannot be one of the CH340C chips. Through extensive testing we found that the following cable is the least expensive and most reliable cable for GKFlasher:&lt;br /&gt;
&lt;br /&gt;
[https://www.aliexpress.us/item/2251832612703671.html Galletto 1260 ECU Chip Tuning Tool EOBD Programmer FTDI] Note: These adapters are not currently supported with BSL.   &lt;br /&gt;
&lt;br /&gt;
Pictured here shows the good FTDI chipset and the CH340C chipsets.&lt;br /&gt;
&lt;br /&gt;
[[File:FTDI Example.png|269x269px]]:[[File:CH340C Example.png]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;*&amp;lt;/nowiki&amp;gt;from GKFlasher v1.0.5 we have added support for the CH340 chipset. &lt;br /&gt;
&lt;br /&gt;
== Manual Windows 10 &amp;amp; 11 Installation ==&lt;br /&gt;
If you&#039;d like to participate in the development of GKFlasher the guide below will demonstrate how to download, install and configure all the prerequisites for GKFlasher. If you are a GitHub user, please go star the following repository:&lt;br /&gt;
&lt;br /&gt;
https://github.com/Dante383/GKFlasher&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; Download the following files: &lt;br /&gt;
&lt;br /&gt;
[https://github.com/git-for-windows/git/releases/download/v2.44.0.windows.1/Git-2.44.0-64-bit.exe Git-2.44.0-64-bit.exe]&lt;br /&gt;
&lt;br /&gt;
[https://www.python.org/ftp/python/3.11.9/python-3.11.9-amd64.exe python-3.11.9-amd64.exe]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Optional download for npcap if you are using a CAN BUS interface for a specific purpose:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[https://npcap.com/dist/npcap-1.79.exe npcap-1.79.exe]&lt;br /&gt;
&lt;br /&gt;
=== Install GIT &amp;amp; Python ===&lt;br /&gt;
&#039;&#039;&#039;3)&#039;&#039;&#039; Open the Git install file named &amp;lt;u&amp;gt;Git-2.44.0-64-bit.exe&amp;lt;/u&amp;gt; selecting &amp;quot;Git from the command line&amp;quot; from the following screen, then continue with all the default options afterwards:&lt;br /&gt;
&lt;br /&gt;
[[File:Git Install 1.png|border]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4)&#039;&#039;&#039; Open the Python installation file named &amp;lt;u&amp;gt;python-3.11.9-amd64.exe&amp;lt;/u&amp;gt; and on the first dialogue select &amp;quot;Add python.exe to PATH&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Python Install 1.png]]&lt;br /&gt;
&lt;br /&gt;
Keep all the default values on the following screen:&lt;br /&gt;
&lt;br /&gt;
[[File:Python Install 2.png]]&lt;br /&gt;
&lt;br /&gt;
Select &amp;quot;Install Pyhon 3.11 for all users&amp;quot; from the following screen: &#039;&#039;&#039;&amp;quot;Add Python to environment variables&amp;quot; has to be selected!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[File:Python Install 3.png]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;5)&#039;&#039;&#039; Once installation is complete you may need to logout of windows or restart your computer before the Powershell will recognize the new PATH entries for GIT and Python. To test if either program works, try the following commands after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol in Windows Powershell and you should see the following responses if all is well. If you do not see these responses or receive a &amp;quot;ObjectNotFound&amp;quot; type of error, then try the above installations again.&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;python -V&#039;&#039;&#039;&lt;br /&gt;
 Python 3.11.9&lt;br /&gt;
&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;git.exe -v&#039;&#039;&#039;&lt;br /&gt;
 git version 2.44.0.windows.1&lt;br /&gt;
&lt;br /&gt;
=== NPCAP Install (Optional) ===&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; If you are using CANBUS for your read/write functions, open and install the file named &amp;lt;u&amp;gt;npcap-1.79.exe&amp;lt;/u&amp;gt; using default options.&lt;br /&gt;
&lt;br /&gt;
=== GKFlasher Setup ===&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; Open your Powershell or Command prompt and change to the desired directory where you will be installing the GKFlasher files. A typical example directory might be in C:\GIT Repos\ so create yourself a directory in the C:\ drive named &amp;quot;GIT Repos&amp;quot; for this example. Use the following commands after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol:&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;mkdir &amp;quot;C:\GIT Repos&amp;quot;&#039;&#039;&#039;&lt;br /&gt;
 &lt;br /&gt;
     Directory: C:\&lt;br /&gt;
 &lt;br /&gt;
 Mode                 LastWriteTime         Length Name&lt;br /&gt;
 ----                 -------------         ------ ----&lt;br /&gt;
 d-----          4/6/2024   7:10 PM                GIT Repos&lt;br /&gt;
&#039;&#039;&#039;2)&#039;&#039;&#039; Change to the &amp;quot;GIT Repos&amp;quot; directory and run the GIT command to download the GKFlasher files to your desired directory using the following command after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol:&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;cd &amp;quot;C:\GIT Repos&amp;quot;&#039;&#039;&#039;&lt;br /&gt;
 &lt;br /&gt;
 PS C:\GIT Repos&amp;gt; &#039;&#039;&#039;git clone &amp;lt;nowiki&amp;gt;https://github.com/Dante383/GKFlasher&amp;lt;/nowiki&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
 Cloning into &#039;GKFlasher&#039;...&lt;br /&gt;
 remote: Enumerating objects: 1071, done.&lt;br /&gt;
 remote: Counting objects: 100% (117/117), done.&lt;br /&gt;
 remote: Compressing objects: 100% (69/69), done.&lt;br /&gt;
 remote: Total 1071 (delta 58), reused 96 (delta 48), pack-reused 954&lt;br /&gt;
 Receiving objects: 100% (1071/1071), 446.77 KiB | 7.45 MiB/s, done.&lt;br /&gt;
 Resolving deltas: 100% (672/672), done.&lt;br /&gt;
&#039;&#039;&#039;3)&#039;&#039;&#039; Change to the GKFlasher directory then install the required Python packages with the following commands after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol:&lt;br /&gt;
 PS C:\GIT Repos&amp;gt; &#039;&#039;&#039;cd GKFlasher&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 PS C:\GIT Repos\GKFlasher&amp;gt; &#039;&#039;&#039;python -m pip install -r requirements.txt&#039;&#039;&#039;&lt;br /&gt;
 Requirement already satisfied: alive_progress==3.1.5 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 1)) (3.1.5)&lt;br /&gt;
 Requirement already satisfied: crcmod==1.7 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 2)) (1.7)&lt;br /&gt;
 Requirement already satisfied: gkbus==0.1.8 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 3)) (0.1.8)&lt;br /&gt;
 Requirement already satisfied: pyftdi==0.55.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 4)) (0.55.0)&lt;br /&gt;
 Requirement already satisfied: pyqt5==5.15.9 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 5)) (5.15.9)&lt;br /&gt;
 Requirement already satisfied: PyYAML==6.0.1 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 6)) (6.0.1)&lt;br /&gt;
 Requirement already satisfied: about-time==4.2.1 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from alive_progress==3.1.5-&amp;gt;-r requirements.txt (line 1)) (4.2.1)&lt;br /&gt;
 Requirement already satisfied: grapheme==0.6.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from alive_progress==3.1.5-&amp;gt;-r requirements.txt (line 1)) (0.6.0)&lt;br /&gt;
 Requirement already satisfied: pyserial==3.5 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from gkbus==0.1.8-&amp;gt;-r requirements.txt (line 3)) (3.5)&lt;br /&gt;
 Requirement already satisfied: scapy==2.5.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from gkbus==0.1.8-&amp;gt;-r requirements.txt (line 3)) (2.5.0)&lt;br /&gt;
 Requirement already satisfied: pyusb!=1.2.0,&amp;gt;=1.0.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from pyftdi==0.55.0-&amp;gt;-r requirements.txt (line 4)) (1.2.1)&lt;br /&gt;
 Requirement already satisfied: PyQt5-sip&amp;lt;13,&amp;gt;=12.11 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from pyqt5==5.15.9-&amp;gt;-r requirements.txt (line 5)) (12.13.0)&lt;br /&gt;
 Requirement already satisfied: PyQt5-Qt5&amp;gt;=5.15.2 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from pyqt5==5.15.9-&amp;gt;-r requirements.txt (line 5)) (5.15.2)&lt;br /&gt;
&#039;&#039;&#039;4)&#039;&#039;&#039; If everything went well you should now be able to start the GKFlasher GUI with the USB cable plugged in. Try the following command and you should see the GKFlasher window appear:&lt;br /&gt;
 PS C:\GIT Repos\GKFlasher&amp;gt; &#039;&#039;&#039;python gui.py&#039;&#039;&#039;&lt;br /&gt;
[[File:GKFlasher First Time.png|701x701px]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;5) Optional:&#039;&#039;&#039; Create a desktop shortcut to open GKFlasher easily. First we&#039;ll need to know the location of your python3.11.exe executable. Execute the following command from your Powershell or command prompt and enter the command after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol. The following line you will use to copy/paste into your desktop shortcut. In this example it is located in my local user&#039;s directory within a subfolder. Yours will vary depending on your username.&lt;br /&gt;
 PS C:\GIT Repos\GKFlasher&amp;gt; &#039;&#039;&#039;(Get-Command python.exe).Path&#039;&#039;&#039;&lt;br /&gt;
 C:\Users\cfham\AppData\Local\Microsoft\WindowsApps\python.exe&lt;br /&gt;
Right click on your desktop and go to &amp;quot;New&amp;quot; and &amp;quot;Shortcut&amp;quot;, then paste the line you found from the last Powershell command and click next:&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 1.png]]&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 2.png|border]]&lt;br /&gt;
&lt;br /&gt;
Type in &amp;quot;GKFlasher&amp;quot; into the next window and press Finish:&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 3.png|border]]&lt;br /&gt;
&lt;br /&gt;
Now right click on that new shortcut and select properties. You will change a couple of settings in this new window so that it starts the GKFlasher app and change to the correct starting directory. First add &amp;quot; gui.py&amp;quot; (Contains a space) to the end of the target prompt and copy/paste the directory location you chose for your GIT Repos containing GKFlasher and press apply. The following is using my example directory. Yours may be unique.&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 4.png|border]]&lt;br /&gt;
&lt;br /&gt;
If you would like to add an icon to your shortcut, you can download the OpenGK/GKFlasher logo from [https://opengk.org/files/Users/chase206/Siemens_T_Logo.ico Siemens_T_Logo.ico] and add it to your GKFLasher shortcut using the &amp;quot;Change Icon&amp;quot; button.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=628</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=628"/>
		<updated>2025-01-05T16:33:35Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* SIMK43 - 8mbit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
Both units memory can be separated into 5 sections:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 50000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 5FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|87FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32 kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - INT_RAM [15872]&lt;br /&gt;
* 0xFD00 - INT_RAM_BIT [256]&lt;br /&gt;
* 0xFF800 - RAM [2048]&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET (within RAM)&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block for CCP within bootloader 2&lt;br /&gt;
* 0x3000000 - FLASH_DR [65520]&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=627</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=627"/>
		<updated>2025-01-05T16:30:58Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* SIMK43 - 8mbit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
Both units memory can be separated into 5 sections:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 50000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 5FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|5FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32 kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - INT_RAM [15872]&lt;br /&gt;
* 0xFD00 - INT_RAM_BIT [256]&lt;br /&gt;
* 0xFF800 - RAM [2048]&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET (within RAM)&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block for CCP within bootloader 2&lt;br /&gt;
* 0x3000000 - FLASH_DR [65520]&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=626</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=626"/>
		<updated>2025-01-05T16:26:14Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* SIMK43 - 8mbit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
Both units memory can be separated into 5 sections:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | C000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 50000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|5FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32 kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - INT_RAM [15872]&lt;br /&gt;
* 0xFD00 - INT_RAM_BIT [256]&lt;br /&gt;
* 0xFF800 - RAM [2048]&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET (within RAM)&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block for CCP within bootloader 2&lt;br /&gt;
* 0x3000000 - FLASH_DR [65520]&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=625</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=625"/>
		<updated>2025-01-05T16:23:03Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Bootloader 2 (32 kByte) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
Both units memory can be separated into 5 sections:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|5FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32 kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - INT_RAM [15872]&lt;br /&gt;
* 0xFD00 - INT_RAM_BIT [256]&lt;br /&gt;
* 0xFF800 - RAM [2048]&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET (within RAM)&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block for CCP within bootloader 2&lt;br /&gt;
* 0x3000000 - FLASH_DR [65520]&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=624</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=624"/>
		<updated>2025-01-05T16:00:04Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Bootloader 2 (32 kByte) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
Both units memory can be separated into 5 sections:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|5FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32 kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - INT_RAM [15872]&lt;br /&gt;
* 0xFD00 - INT_RAM_BIT [256]&lt;br /&gt;
* 0xFF800 - RAM [2048]&lt;br /&gt;
* 0x50000 - RAMCAL1 [65520]&lt;br /&gt;
* 0x90000 - ROM [65520]&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET (within RAM)&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block for CCP within bootloader 2&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=623</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=623"/>
		<updated>2024-12-28T17:34:31Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Bootloader 2 (32kByte) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
Both units memory can be separated into 5 sections:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|5FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32 kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - bootloader 2 version e.g. 66340560&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=622</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=622"/>
		<updated>2024-12-28T17:34:03Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Bootloader 2 (32kByte) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
Both units memory can be separated into 5 sections:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|5FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
ca663056 locations:&lt;br /&gt;
&lt;br /&gt;
* 0xC000 - bootloader 2 version e.g. 66340560&lt;br /&gt;
* 0xCA4E - CCP Seed/key e.g. DEET&lt;br /&gt;
* 0xEE00 - CCP Registers&lt;br /&gt;
&lt;br /&gt;
ca663057/58+:&lt;br /&gt;
&lt;br /&gt;
* 32kb data block&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=MediaWiki:Sidebar&amp;diff=621</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=MediaWiki:Sidebar&amp;diff=621"/>
		<updated>2024-12-28T15:22:35Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
* navigation&lt;br /&gt;
** mainpage|mainpage-description&lt;br /&gt;
** recentchanges-url|recentchanges&lt;br /&gt;
** randompage-url|randompage&lt;br /&gt;
* Siemens L4 2.0L&lt;br /&gt;
** 5WY_ECM_Identification#Siemens_5WY_2_Connector_.282.0L_L4.29 | ECM Identification&lt;br /&gt;
** 2.0L_PCB_Layouts | 2.0L PCB Layouts&lt;br /&gt;
** Siemens_5WY_2_Connector_Pinout | 2.0L L4 Pinout&lt;br /&gt;
** 2.0L_ECM | 2.0L ECM&lt;br /&gt;
** CAN_Bus_messages | CAN Bus&lt;br /&gt;
* Siemens V6 2.7L&lt;br /&gt;
** 5WY_ECM_Identification#Siemens_5WY_5_Connector_.282.7L_V6.29 | ECM Identification&lt;br /&gt;
** 2.7L_V6_PCB_Layouts | 2.7L PCB Layouts&lt;br /&gt;
** Siemens_5WY_5_Connector_Pinout | 2.7L V6 Pinout&lt;br /&gt;
* Downloads&lt;br /&gt;
** https://opengk.org/files/ | File Repository&lt;br /&gt;
* SEARCH&lt;br /&gt;
* TOOLBOX&lt;br /&gt;
* LANGUAGES&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=620</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=620"/>
		<updated>2024-12-28T14:14:01Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
Both units memory can be separated into 5 sections:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|5FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#bfbdbf;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Bootloader 2 (32kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs or SIMK43&#039;s running less than ca663056.&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; refers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=619</id>
		<title>2.0L ECM</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=2.0L_ECM&amp;diff=619"/>
		<updated>2024-12-28T12:49:46Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Memory layouts per ECU */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Vehicles equipped with the 2.0L Beta used the 2mbit SIMK41 up until the first [[Hyundai Tiburon|facelift model]] (2005), when CVVT was introduced and 4mbit SIMK43 was used. &lt;br /&gt;
&lt;br /&gt;
== Memory layout ==&lt;br /&gt;
Both units memory can be separated into 5 sections:  &lt;br /&gt;
&lt;br /&gt;
* bootloader &amp;amp; UIF&lt;br /&gt;
* adaptive values&lt;br /&gt;
* calibration zone&lt;br /&gt;
* program code&lt;br /&gt;
&lt;br /&gt;
=== Memory layouts per ECU ===&lt;br /&gt;
&lt;br /&gt;
==== SIMK41 - 2mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 3FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 192 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 4mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader &amp;amp; UIF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 8000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 10000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 20000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SIMK43 - 8mbit ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Start&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | End&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Section&lt;br /&gt;
! style=&amp;quot;text-align: center; font-weight:bold;&amp;quot; | Size&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 0&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 3FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 1&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 4000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 7FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | Adaptive values&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#ff9797;&amp;quot; | 16 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|82000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|5FFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|Recovery (RSW)&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#aadae3;&amp;quot;|24 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 88000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | Bootloader 2&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fe996b;&amp;quot; | 32 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 90000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 1FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | Calibration Zone&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#9aff99; color:#000000;&amp;quot; | 64 kByte&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | A0000&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 7FFFF&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | Program Code&lt;br /&gt;
| style=&amp;quot;text-align: center; background-color:#fffc9e;&amp;quot; | 384 kByte&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Description of memory sections ===&lt;br /&gt;
&lt;br /&gt;
==== Bootloader &amp;amp; UIF ====&lt;br /&gt;
This section is 16 kilobytes in size and contains the boot code that initializes the ECU and verifies that everything is ok before control is handed over to the program code section.&lt;br /&gt;
This section also contains one time writeable data such as hardware identifier, manufacturer information and user information fields (UIF). &lt;br /&gt;
&lt;br /&gt;
Offsets and data structure in the table below are shared across all variants.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size (bytes, decimal)&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|[[K-Line|KWP seed/key]]&lt;br /&gt;
|0x3E01&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=58D8C848}}&lt;br /&gt;
|Two bytes seed, followed by two bytes key&lt;br /&gt;
|-&lt;br /&gt;
|[[Vehicle identification number (VIN)|VIN]]&lt;br /&gt;
|0x3E22&lt;br /&gt;
|17&lt;br /&gt;
|&lt;br /&gt;
|2.0 ECUs don&#039;t store VIN. Instead, sometimes there&#039;s a [[Vehicle identification number (VIN)|wildcard that narrows the VIN down to Tiburon models]], sometimes it&#039;s just &#039;xxxxxxxxxxxxxxxxx&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Socket&lt;br /&gt;
|0x3F70&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x5539|default-display=ascii}}&lt;br /&gt;
|Value from the small sticker usually located on the ECU socket. [[:File:Socket label example SIMK43 U9 5WY1923A.png|Click for example with &amp;quot;U9&amp;quot; label]]&lt;br /&gt;
|-&lt;br /&gt;
|[[ECU family]]&lt;br /&gt;
|0x3F80&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3557593139323341|default-display=ascii}}&lt;br /&gt;
|In short - ECU hardware variant from the main label. For more in-depth analysis, see [[ECU family]]&lt;br /&gt;
|-&lt;br /&gt;
|Serial number&lt;br /&gt;
|0x3F8A&lt;br /&gt;
|50&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x2D313038313033363236322D484D4330383033313030363039323931384B523737303237363034422D4B5237373032353036|default-display=ascii}}&lt;br /&gt;
|This actually contains three separate (not all unique) identifiers and will be split into three sections - TODO.&lt;br /&gt;
|-&lt;br /&gt;
|Date (YYMMDD)&lt;br /&gt;
|0x3F98&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x303830333130|default-display=ascii}}&lt;br /&gt;
(2008, March 31st)&lt;br /&gt;
|Production/first flash date. This &#039;&#039;&#039;might&#039;&#039;&#039;/should be updated after flashing, might be updated after flashing with an official dealer tool - to be verified.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Adaptive values ====&lt;br /&gt;
This section potentially acts as RAM? It also stores adaptive values - short/long range fuel trims and other adjustments. This section has not been analyzed in depth yet, but there&#039;s a high possibility the data inside is [https://github.com/Dante383/siemens-simk43-decrypt scrambled (crossed EEPROM lines, resulting in swapped bits in every pair of bytes)]&lt;br /&gt;
&lt;br /&gt;
==== Program code (32kByte) ====&lt;br /&gt;
This section has not been analyzed in depth yet. It&#039;s not present on SIMK41 ECUs&lt;br /&gt;
&lt;br /&gt;
==== Calibration zone ====&lt;br /&gt;
Calibration zone contains all the calibration data and maps used for managing the engine. &lt;br /&gt;
&lt;br /&gt;
Position and structure varies depending on the calibration version, but the structure of first 96 (0x60) bytes is standarized. &lt;br /&gt;
&lt;br /&gt;
&amp;quot;start&amp;quot; reefers to the calibration zone offset (SIMK41 - 0x8000, SIMK43 - 0x10000)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Name&lt;br /&gt;
!Offset&lt;br /&gt;
!Size&lt;br /&gt;
!Example&lt;br /&gt;
!Notes&lt;br /&gt;
|-&lt;br /&gt;
|Chassis identifier&lt;br /&gt;
|start&lt;br /&gt;
|8&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x4B394E3756533041|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;calibration version&amp;quot; (confusing, I know)&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version (#1 occurence)&lt;br /&gt;
|start + 0x8&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x363535303239|default-display=ascii}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|Calibration [[Checksum|checksum initial value]]&lt;br /&gt;
|start + 0xC&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x3239}}&lt;br /&gt;
|Overlap of offsets isn&#039;t a typo here - last two digits of the first occurence of calibration version are also the [[Checksum|initial value for the calibration zone checksum]]&lt;br /&gt;
|-&lt;br /&gt;
|Calibration version&lt;br /&gt;
(#2 occurence)&lt;br /&gt;
|start + 0x40&lt;br /&gt;
|12&lt;br /&gt;
|&lt;br /&gt;
{{HexConverter|hex=0x63613635353032392E444154|default-display=ascii}}&lt;br /&gt;
|Siemens calls it &amp;quot;description identifier&amp;quot;.&lt;br /&gt;
Notice the &amp;quot;ca&amp;quot; prefix and &amp;quot;.DAT&amp;quot; suffix - this is likely the filename from proprietary OEM software that was used to compile the EEPROM image. &lt;br /&gt;
&#039;&#039;&#039;While not confirmed&#039;&#039;&#039;, it appears that lowercase &#039;ca&#039; suffix was used through the SIMK4x series, with uppercase &#039;CA&#039; first appearing in SIM2K series &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Program code ====&lt;br /&gt;
This section contains the program code used for operating the engine&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=MediaWiki:Sidebar&amp;diff=618</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=MediaWiki:Sidebar&amp;diff=618"/>
		<updated>2024-12-28T12:20:57Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
* navigation&lt;br /&gt;
** mainpage|mainpage-description&lt;br /&gt;
** recentchanges-url|recentchanges&lt;br /&gt;
** randompage-url|randompage&lt;br /&gt;
* Siemens L4 2.0L&lt;br /&gt;
** 5WY_ECM_Identification#Siemens_5WY_2_Connector_.282.0L_L4.29 | ECM Identification&lt;br /&gt;
** CAN_Bus_messages | CAN Bus&lt;br /&gt;
** 2.0L_PCB_Layouts | 2.0L PCB Layouts&lt;br /&gt;
** Siemens_5WY_2_Connector_Pinout | 2.0L L4 Pinout&lt;br /&gt;
** 2.0L_ECM | 2.0L ECM&lt;br /&gt;
* Siemens V6 2.7L&lt;br /&gt;
** 5WY_ECM_Identification#Siemens_5WY_5_Connector_.282.7L_V6.29 | ECM Identification&lt;br /&gt;
** 2.7L_V6_PCB_Layouts | 2.7L PCB Layouts&lt;br /&gt;
** Siemens_5WY_5_Connector_Pinout | 2.7L V6 Pinout&lt;br /&gt;
* Downloads&lt;br /&gt;
** https://opengk.org/files/ | File Repository&lt;br /&gt;
* SEARCH&lt;br /&gt;
* TOOLBOX&lt;br /&gt;
* LANGUAGES&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=MediaWiki:Sidebar&amp;diff=617</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=MediaWiki:Sidebar&amp;diff=617"/>
		<updated>2024-12-28T12:20:27Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
* navigation&lt;br /&gt;
** mainpage|mainpage-description&lt;br /&gt;
** recentchanges-url|recentchanges&lt;br /&gt;
** randompage-url|randompage&lt;br /&gt;
* Siemens L4 2.0L&lt;br /&gt;
** 5WY_ECM_Identification#Siemens_5WY_2_Connector_.282.0L_L4.29 | ECM Identification&lt;br /&gt;
** CAN_Bus_messages | CAN Bus&lt;br /&gt;
** 2.0L_PCB_Layouts | 2.0L PCB Layouts&lt;br /&gt;
** Siemens_5WY_2_Connector_Pinout | 2.0L L4 Pinout&lt;br /&gt;
** 2.0L_ECM | 2.0L ECM&lt;br /&gt;
* Siemens V6 2.7L Hardware&lt;br /&gt;
** 5WY_ECM_Identification#Siemens_5WY_5_Connector_.282.7L_V6.29 | ECM Identification&lt;br /&gt;
** 2.7L_V6_PCB_Layouts | 2.7L PCB Layouts&lt;br /&gt;
** Siemens_5WY_5_Connector_Pinout | 2.7L V6 Pinout&lt;br /&gt;
* Downloads&lt;br /&gt;
** https://opengk.org/files/ | File Repository&lt;br /&gt;
* SEARCH&lt;br /&gt;
* TOOLBOX&lt;br /&gt;
* LANGUAGES&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Main_Page&amp;diff=616</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Main_Page&amp;diff=616"/>
		<updated>2024-12-28T12:19:27Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* General */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Welcome to the OpenGK Wiki&#039;&#039;&#039;&lt;br /&gt;
[[File:Siemens T Logo.gif|frameless|right]]&lt;br /&gt;
[[File:Discord-Logo+Wordmark-Color.png|150px|frameless|right|link=https://discord.gg/a4fWuBTfxV]]&lt;br /&gt;
Our goal is to open source the Hyundai/Kia Siemens ECMs on the Beta and Delta motors to provide tuning options to the DIY enthusiasts. This project originally started for the [[Hyundai Tiburon|Hyundai Coupe/Tuscani/Tiburon platform]] but as we collected more data from other platforms with similar ECMs, it was clear that those other platforms can be supported using the same principals.&lt;br /&gt;
&lt;br /&gt;
We are looking for smart individuals that have experience with IDA Pro and disassembly that are willing to help push this project further. Please contact &#039;&#039;&#039;info(at)opengk.org&#039;&#039;&#039; or join our Discord if you would like to contribute to this project.&lt;br /&gt;
&lt;br /&gt;
If you are a tuner and found this site to be useful, please consider a donation to Paypal: &#039;&#039;&#039;donate(at)opengk.org&#039;&#039;&#039; to help keep the site alive.&lt;br /&gt;
&lt;br /&gt;
==== General ====&lt;br /&gt;
[https://vin.opengk.org VIN Decoder]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Hyundai Tiburon]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Vehicle identification number (VIN)]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Data link connector (OBD2)]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Immobiliser]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[SMARTRA|Smartra]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Body Control Module]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Instrument Cluster]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Communication protocols ====&lt;br /&gt;
[[K-Line]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[SIMK43 CAN Bus|CAN Bus messages]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== ECM Tuning ====&lt;br /&gt;
[[GKFlasher Instructions]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Cross Flash Kia Spectra|Cross-Flash Kia Spectra &amp;gt; Tiburon Firmware]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Siemens L4 2.0L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 2 Connector .282.0L L4.29| ECM Identification]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[2.0l PCB Layouts| 2.0L PCB Layouts]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 2 Connector Pinout| 2.0L L4 Pinout]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[2.0L ECM]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Siemens V6 2.7L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 5 Connector .282.7L V6.29|ECM Identification]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[2.7L V6 PCB Layouts]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 5 Connector Pinout| 2.7L V6 Pinout]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Parts Compatibility ====&lt;br /&gt;
[[Sensor Information]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Fuel Injector Specifications]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Camshaft Specifications]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Bosch Chip Part Numbers]]&lt;br /&gt;
&lt;br /&gt;
==== Downloads ====&lt;br /&gt;
[https://opengk.org/files/ File Repository]&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Main_Page&amp;diff=615</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Main_Page&amp;diff=615"/>
		<updated>2024-12-28T12:12:36Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Welcome to the OpenGK Wiki&#039;&#039;&#039;&lt;br /&gt;
[[File:Siemens T Logo.gif|frameless|right]]&lt;br /&gt;
[[File:Discord-Logo+Wordmark-Color.png|150px|frameless|right|link=https://discord.gg/a4fWuBTfxV]]&lt;br /&gt;
Our goal is to open source the Hyundai/Kia Siemens ECMs on the Beta and Delta motors to provide tuning options to the DIY enthusiasts. This project originally started for the [[Hyundai Tiburon|Hyundai Coupe/Tuscani/Tiburon platform]] but as we collected more data from other platforms with similar ECMs, it was clear that those other platforms can be supported using the same principals.&lt;br /&gt;
&lt;br /&gt;
We are looking for smart individuals that have experience with IDA Pro and disassembly that are willing to help push this project further. Please contact &#039;&#039;&#039;info(at)opengk.org&#039;&#039;&#039; or join our Discord if you would like to contribute to this project.&lt;br /&gt;
&lt;br /&gt;
If you are a tuner and found this site to be useful, please consider a donation to Paypal: &#039;&#039;&#039;donate(at)opengk.org&#039;&#039;&#039; to help keep the site alive.&lt;br /&gt;
&lt;br /&gt;
==== General ====&lt;br /&gt;
[https://vin.opengk.org VIN Decoder]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Hyundai Tiburon]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Vehicle identification number (VIN)]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Data link connector (OBD2)]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Immobiliser]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Body Control Module]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Instrument Cluster]]&lt;br /&gt;
&lt;br /&gt;
==== Communication protocols ====&lt;br /&gt;
[[K-Line]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[SIMK43 CAN Bus|CAN Bus messages]]&lt;br /&gt;
&lt;br /&gt;
==== ECM Tuning ====&lt;br /&gt;
[[GKFlasher Instructions]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Cross Flash Kia Spectra|Cross-Flash Kia Spectra &amp;gt; Tiburon Firmware]]&lt;br /&gt;
&lt;br /&gt;
==== Siemens L4 2.0L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 2 Connector .282.0L L4.29| ECM Identification]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[2.0l PCB Layouts| 2.0L PCB Layouts]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 2 Connector Pinout| 2.0L L4 Pinout]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[2.0L ECM]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Siemens V6 2.7L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 5 Connector .282.7L V6.29|ECM Identification]]&amp;lt;br&amp;gt;[[2.7L V6 PCB Layouts]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 5 Connector Pinout| 2.7L V6 Pinout]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Parts Compatibility ====&lt;br /&gt;
[[Sensor Information]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Fuel Injector Specifications]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Camshaft Specifications]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Bosch Chip Part Numbers]]&lt;br /&gt;
&lt;br /&gt;
==== Downloads ====&lt;br /&gt;
[https://opengk.org/files/ File Repository]&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=MediaWiki:Sidebar&amp;diff=614</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=MediaWiki:Sidebar&amp;diff=614"/>
		<updated>2024-12-28T12:10:50Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
* navigation&lt;br /&gt;
** mainpage|mainpage-description&lt;br /&gt;
** recentchanges-url|recentchanges&lt;br /&gt;
** randompage-url|randompage&lt;br /&gt;
* Siemens L4 2.0L Hardware&lt;br /&gt;
** 5WY_ECM_Identification#Siemens_5WY_2_Connector_.282.0L_L4.29 | ECM Identification&lt;br /&gt;
** CAN_Bus_messages | CAN Bus&lt;br /&gt;
** 2.0L_PCB_Layouts | 2.0L PCB Layouts&lt;br /&gt;
** Siemens_5WY_2_Connector_Pinout | 2.0L L4 Pinout&lt;br /&gt;
** 2.0L_ECM | 2.0L ECM&lt;br /&gt;
* Siemens V6 2.7L Hardware&lt;br /&gt;
** 5WY_ECM_Identification#Siemens_5WY_5_Connector_.282.7L_V6.29 | ECM Identification&lt;br /&gt;
** 2.7L_V6_PCB_Layouts | 2.7L PCB Layouts&lt;br /&gt;
** Siemens_5WY_5_Connector_Pinout | 2.7L V6 Pinout&lt;br /&gt;
* Downloads&lt;br /&gt;
** https://opengk.org/files/ | File Repository&lt;br /&gt;
* SEARCH&lt;br /&gt;
* TOOLBOX&lt;br /&gt;
* LANGUAGES&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Main_Page&amp;diff=613</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Main_Page&amp;diff=613"/>
		<updated>2024-12-28T12:01:01Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* ECM Tuning: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Welcome to the OpenGK Wiki&#039;&#039;&#039;&lt;br /&gt;
[[File:Siemens T Logo.gif|frameless|right]]&lt;br /&gt;
[[File:Discord-Logo+Wordmark-Color.png|150px|frameless|right|link=https://discord.gg/a4fWuBTfxV]]&lt;br /&gt;
Our goal is to open source the Hyundai/Kia Siemens ECMs on the Beta and Delta motors to provide tuning options to the DIY enthusiasts. This project originally started for the [[Hyundai Tiburon|Hyundai Coupe/Tuscani/Tiburon platform]] but as we collected more data from other platforms with similar ECMs, it was clear that those other platforms can be supported using the same principals.&lt;br /&gt;
&lt;br /&gt;
We are looking for smart individuals that have experience with IDA Pro and disassembly that are willing to help push this project further. Please contact &#039;&#039;&#039;info(at)opengk.org&#039;&#039;&#039; or join our Discord if you would like to contribute to this project.&lt;br /&gt;
&lt;br /&gt;
If you are a tuner and found this site to be useful, please consider a donation to Paypal: &#039;&#039;&#039;donate(at)opengk.org&#039;&#039;&#039; to help keep the site alive.&lt;br /&gt;
&lt;br /&gt;
==== General ====&lt;br /&gt;
[https://vin.opengk.org VIN Decoder]&lt;br /&gt;
&lt;br /&gt;
[[Hyundai Tiburon]]&lt;br /&gt;
&lt;br /&gt;
[[Vehicle identification number (VIN)]]&lt;br /&gt;
&lt;br /&gt;
[[Data link connector (OBD2)]]&lt;br /&gt;
&lt;br /&gt;
[[Immobiliser]]&lt;br /&gt;
&lt;br /&gt;
[[Body Control Module]]&lt;br /&gt;
&lt;br /&gt;
[[Instrument Cluster]]&lt;br /&gt;
&lt;br /&gt;
==== Communication protocols ====&lt;br /&gt;
[[K-Line]]&lt;br /&gt;
&lt;br /&gt;
[[SIMK43 CAN Bus|CAN Bus messages]]&lt;br /&gt;
&lt;br /&gt;
==== ECM Tuning ====&lt;br /&gt;
[[GKFlasher Instructions]]&lt;br /&gt;
&lt;br /&gt;
[[Cross Flash Kia Spectra|Cross-Flash Kia Spectra &amp;gt; Tiburon Firmware]]&lt;br /&gt;
&lt;br /&gt;
==== Siemens L4 2.0L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 2 Connector .282.0L L4.29| ECM Identification]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[2.0l PCB Layouts| 2.0L PCB Layouts]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 2 Connector Pinout| 2.0L L4 Pinout]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[2.0L ECM]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Siemens V6 2.7L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 5 Connector .282.7L V6.29|ECM Identification]]&amp;lt;br&amp;gt;[[2.7L V6 PCB Layouts]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 5 Connector Pinout| 2.7L V6 Pinout]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Parts Compatibility ====&lt;br /&gt;
[[Sensor Information]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Fuel Injector Specifications]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Camshaft Specifications]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Bosch Chip Part Numbers]]&lt;br /&gt;
&lt;br /&gt;
==== Downloads ====&lt;br /&gt;
[https://opengk.org/files/ File Repository]&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=492</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=492"/>
		<updated>2024-12-19T12:13:08Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
[[File:Kia crossflash cal.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash prog.png|thumb]]&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
Once the version detials have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
You may need to re-program the Immobilizer running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;&lt;br /&gt;
&lt;br /&gt;
Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;br /&gt;
[[File:Kia crossflash gui.png|thumb]]&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=File:Kia_crossflash_gui.png&amp;diff=491</id>
		<title>File:Kia crossflash gui.png</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=File:Kia_crossflash_gui.png&amp;diff=491"/>
		<updated>2024-12-19T12:13:00Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;kia_crossflash_gui&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=File:Kia_crossflash_prog.png&amp;diff=490</id>
		<title>File:Kia crossflash prog.png</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=File:Kia_crossflash_prog.png&amp;diff=490"/>
		<updated>2024-12-19T12:11:59Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;kia_crossflash_prog&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=File:Kia_crossflash_cal.png&amp;diff=489</id>
		<title>File:Kia crossflash cal.png</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=File:Kia_crossflash_cal.png&amp;diff=489"/>
		<updated>2024-12-19T12:10:53Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;kia_crossflash_cal&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=488</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=488"/>
		<updated>2024-12-19T12:05:00Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
[[File:Kia crossflash 3.png|thumb]]&lt;br /&gt;
Once the version detials have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
You may need to re-program the Immobilizer running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;&lt;br /&gt;
&lt;br /&gt;
Bear in mind, if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=484</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=484"/>
		<updated>2024-12-19T10:53:03Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
[[File:Kia crossflash 1.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash 2.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash 3.png|thumb]]&lt;br /&gt;
Once the version detials have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
You may need to re-program the Immobilizer running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;&lt;br /&gt;
&lt;br /&gt;
Bear in mind if the immobilizer hasn&#039;t been programmed correctly you&#039;ll be unable to re-flash and will receive the error above prior to the erase operation. This won&#039;t brick the ECU, its a security feature to prevent you tampering with the ECU if the keys aren&#039;t present.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=483</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=483"/>
		<updated>2024-12-19T10:47:38Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
[[File:Kia crossflash 1.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash 2.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash 3.png|thumb]]&lt;br /&gt;
Once the version detials have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
You may need to re-program the Immobilizer running through the Teach Keys procedure if the Immo status is &#039;virgin&#039; or &#039;not learnt&#039;&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=482</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=482"/>
		<updated>2024-12-19T10:45:49Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
[[File:Kia crossflash 1.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash 2.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash 3.png|thumb]]&lt;br /&gt;
Once the version detials have been updated, correct the checksum and upload via GKFlasher using the &#039;Full Flash&#039; option.&lt;br /&gt;
&lt;br /&gt;
You may need to re-program the Immobilizer running through the Teach Keys procedure if the Immo status is &#039;virgin&#039;&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=480</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=480"/>
		<updated>2024-12-19T10:39:38Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Kia Spectra runs calibration version ca662008 which has a very similar bootloader to ca663056 used on the GK Chassis. &lt;br /&gt;
&lt;br /&gt;
The goal of this article is to cross-flash the Tiburon program code and calibration zone avoiding the error:&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
&#039;Negative response&#039;, &#039;&amp;lt;0x22 - Conditions Not Correct Or Request Sequence Error&amp;gt;&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The reason for this error, when performing a flash operation via k-line the bootloader validates the firmware that is being uploaded using the 0x2 subroutine. &lt;br /&gt;
&lt;br /&gt;
The idea is to prevent a mismatch where the bootloader is unable to load the program code which would essentially brick the ECU requiring a BSL re-flash recovery.&lt;br /&gt;
&lt;br /&gt;
In order to by-pass the validation check we can insert the ca662008 version number into the ca663056 program code and calibration zone tricking the ECU into thinking it&#039;s running an older version. The two sections of code that need updating, 0x20000 (program code) and 0x10000 (calibration zone)&lt;br /&gt;
[[File:Kia crossflash 1.png|thumb]]&lt;br /&gt;
[[File:Kia crossflash 2.png|thumb]]&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Main_Page&amp;diff=477</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Main_Page&amp;diff=477"/>
		<updated>2024-12-19T10:13:59Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* ECM Tuning: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Welcome to the OpenGK Wiki&#039;&#039;&#039;&lt;br /&gt;
[[File:Siemens T Logo.gif|frameless|right]]&lt;br /&gt;
[[File:Discord-Logo+Wordmark-Color.png|150px|frameless|right|link=https://discord.gg/a4fWuBTfxV]]&lt;br /&gt;
Our goal is to open source the Hyundai/Kia Siemens ECMs on the Beta and Delta motors to provide tuning options to the DIY enthusiasts. This project originally started for the [[Hyundai Tiburon|Hyundai Coupe/Tuscani/Tiburon platform]] but as we collected more data from other platforms with similar ECMs, it was clear that those other platforms can be supported using the same principals.&lt;br /&gt;
&lt;br /&gt;
We are looking for smart individuals that have experience with IDA Pro and disassembly that are willing to help push this project further. Please contact &#039;&#039;&#039;info(at)opengk.org&#039;&#039;&#039; or join our Discord if you would like to contribute to this project.&lt;br /&gt;
&lt;br /&gt;
If you are a tuner and found this site to be useful, please consider a donation to Paypal: &#039;&#039;&#039;donate(at)opengk.org&#039;&#039;&#039; to help keep the site alive.&lt;br /&gt;
&lt;br /&gt;
==== General: ====&lt;br /&gt;
[https://vin.opengk.org VIN Decoder]&lt;br /&gt;
&lt;br /&gt;
[[Hyundai Tiburon]]&lt;br /&gt;
&lt;br /&gt;
[[Vehicle identification number (VIN)]]&lt;br /&gt;
&lt;br /&gt;
[[Data link connector (OBD2)]]&lt;br /&gt;
&lt;br /&gt;
[[Immobiliser]]&lt;br /&gt;
&lt;br /&gt;
[[Body Control Module]]&lt;br /&gt;
&lt;br /&gt;
[[Instrument Cluster]]&lt;br /&gt;
&lt;br /&gt;
==== Communication protocols ====&lt;br /&gt;
[[K-Line]]&lt;br /&gt;
&lt;br /&gt;
[[SIMK43 CAN Bus|CAN Bus messages]]&lt;br /&gt;
&lt;br /&gt;
==== ECM Tuning: ====&lt;br /&gt;
[[GKFlasher Instructions]]&lt;br /&gt;
&lt;br /&gt;
[[Cross Flash Kia Spectra|Cross-Flash Kia Spectra &amp;gt; Tiburon Firmware]]&lt;br /&gt;
&lt;br /&gt;
==== Siemens L4 2.0L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 2 Connector .282.0L L4.29| ECM Identification]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[2.0l PCB Layouts| 2.0L PCB Layouts]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 2 Connector Pinout| 2.0L L4 Pinout]]&lt;br /&gt;
&lt;br /&gt;
==== Siemens V6 2.7L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 5 Connector .282.7L V6.29|ECM Identification]]&amp;lt;br&amp;gt;[[2.7L V6 PCB Layouts]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 5 Connector Pinout| 2.7L V6 Pinout]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Parts Compatibility ====&lt;br /&gt;
[[Sensor Information]]&lt;br /&gt;
&lt;br /&gt;
[[Fuel Injector Specifications]]&lt;br /&gt;
&lt;br /&gt;
[[Camshaft Specifications]]&lt;br /&gt;
&lt;br /&gt;
[[Bosch Chip Part Numbers]]&lt;br /&gt;
&lt;br /&gt;
==== Downloads ====&lt;br /&gt;
[https://opengk.org/files/ File Repository]&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=476</id>
		<title>Cross Flash Kia Spectra</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Cross_Flash_Kia_Spectra&amp;diff=476"/>
		<updated>2024-12-19T10:13:16Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: Created page with &amp;quot;Cross-Flash Kia Spectra &amp;gt; Tiburon Firmware&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Cross-Flash Kia Spectra &amp;gt; Tiburon Firmware&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=Main_Page&amp;diff=475</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=Main_Page&amp;diff=475"/>
		<updated>2024-12-19T10:10:29Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* ECM Tuning: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Welcome to the OpenGK Wiki&#039;&#039;&#039;&lt;br /&gt;
[[File:Siemens T Logo.gif|frameless|right]]&lt;br /&gt;
[[File:Discord-Logo+Wordmark-Color.png|150px|frameless|right|link=https://discord.gg/a4fWuBTfxV]]&lt;br /&gt;
Our goal is to open source the Hyundai/Kia Siemens ECMs on the Beta and Delta motors to provide tuning options to the DIY enthusiasts. This project originally started for the [[Hyundai Tiburon|Hyundai Coupe/Tuscani/Tiburon platform]] but as we collected more data from other platforms with similar ECMs, it was clear that those other platforms can be supported using the same principals.&lt;br /&gt;
&lt;br /&gt;
We are looking for smart individuals that have experience with IDA Pro and disassembly that are willing to help push this project further. Please contact &#039;&#039;&#039;info(at)opengk.org&#039;&#039;&#039; or join our Discord if you would like to contribute to this project.&lt;br /&gt;
&lt;br /&gt;
If you are a tuner and found this site to be useful, please consider a donation to Paypal: &#039;&#039;&#039;donate(at)opengk.org&#039;&#039;&#039; to help keep the site alive.&lt;br /&gt;
&lt;br /&gt;
==== General: ====&lt;br /&gt;
[https://vin.opengk.org VIN Decoder]&lt;br /&gt;
&lt;br /&gt;
[[Hyundai Tiburon]]&lt;br /&gt;
&lt;br /&gt;
[[Vehicle identification number (VIN)]]&lt;br /&gt;
&lt;br /&gt;
[[Data link connector (OBD2)]]&lt;br /&gt;
&lt;br /&gt;
[[Immobiliser]]&lt;br /&gt;
&lt;br /&gt;
[[Body Control Module]]&lt;br /&gt;
&lt;br /&gt;
[[Instrument Cluster]]&lt;br /&gt;
&lt;br /&gt;
==== Communication protocols ====&lt;br /&gt;
[[K-Line]]&lt;br /&gt;
&lt;br /&gt;
[[SIMK43 CAN Bus|CAN Bus messages]]&lt;br /&gt;
&lt;br /&gt;
==== ECM Tuning: ====&lt;br /&gt;
[[GKFlasher Instructions]]&lt;br /&gt;
&lt;br /&gt;
Cross-Flash Kia Spectra &amp;gt; Tiburon Firmware&lt;br /&gt;
&lt;br /&gt;
==== Siemens L4 2.0L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 2 Connector .282.0L L4.29| ECM Identification]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[2.0l PCB Layouts| 2.0L PCB Layouts]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 2 Connector Pinout| 2.0L L4 Pinout]]&lt;br /&gt;
&lt;br /&gt;
==== Siemens V6 2.7L Hardware ====&lt;br /&gt;
[[5WY ECM Identification#Siemens 5WY 5 Connector .282.7L V6.29|ECM Identification]]&amp;lt;br&amp;gt;[[2.7L V6 PCB Layouts]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Siemens 5WY 5 Connector Pinout| 2.7L V6 Pinout]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Parts Compatibility ====&lt;br /&gt;
[[Sensor Information]]&lt;br /&gt;
&lt;br /&gt;
[[Fuel Injector Specifications]]&lt;br /&gt;
&lt;br /&gt;
[[Camshaft Specifications]]&lt;br /&gt;
&lt;br /&gt;
[[Bosch Chip Part Numbers]]&lt;br /&gt;
&lt;br /&gt;
==== Downloads ====&lt;br /&gt;
[https://opengk.org/files/ File Repository]&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=GKFlasher_Instructions&amp;diff=474</id>
		<title>GKFlasher Instructions</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=GKFlasher_Instructions&amp;diff=474"/>
		<updated>2024-12-18T20:51:18Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: /* Windows 10 &amp;amp; 11 Installation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
GKFlasher is an open source Python project supported by OpenGK, written by dante383 and dmg210. This project is a multi OBD2 tool for the Siemens ECUs found on the Hyundai and Kia vehicles. It can read &amp;amp; write tune data, correct EEPROM checksums and clear adaptive values from your ECU. The purpose of this article is to instruct you how to download, install and configure all the prerequisites for GKFlasher. If you are a GitHub user, please go star the following repository:&lt;br /&gt;
&lt;br /&gt;
https://github.com/Dante383/GKFlasher&lt;br /&gt;
&lt;br /&gt;
== Windows 10 &amp;amp; 11 Installation ==&lt;br /&gt;
=== Prerequisites ===&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; First you will need a FTDI USB-OBD2 interface cable. This is often the same cable used on German vehicles. The chipset on the board must be a real FTDI chip and cannot be one of the CH340C chips. Through extensive testing we found that the following cable is the least expensive and most reliable cable for GKFlasher:&lt;br /&gt;
&lt;br /&gt;
[https://www.aliexpress.us/item/2251832612703671.html Galletto 1260 ECU Chip Tuning Tool EOBD Programmer FTDI] Note: These adapters are not currently supported with BSL.   &lt;br /&gt;
&lt;br /&gt;
Pictured here shows the good FTDI chipset and the bad CH340C chipset. Avoid the CH340C chipsets completely.&lt;br /&gt;
&lt;br /&gt;
[[File:FTDI Example.png|269x269px]]:[[File:CH340C Example.png]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;*&amp;lt;/nowiki&amp;gt;from GKFlasher v1.0.5 we have added support for the CH340 chipset. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2)&#039;&#039;&#039; Download the following files:&lt;br /&gt;
&lt;br /&gt;
[https://github.com/git-for-windows/git/releases/download/v2.44.0.windows.1/Git-2.44.0-64-bit.exe Git-2.44.0-64-bit.exe]&lt;br /&gt;
&lt;br /&gt;
[https://www.python.org/ftp/python/3.11.9/python-3.11.9-amd64.exe python-3.11.9-amd64.exe]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Optional download for npcap if you are using a CAN BUS interface for a specific purpose:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[https://npcap.com/dist/npcap-1.79.exe npcap-1.79.exe]&lt;br /&gt;
&lt;br /&gt;
=== Install GIT &amp;amp; Python ===&lt;br /&gt;
&#039;&#039;&#039;3)&#039;&#039;&#039; Open the Git install file named &amp;lt;u&amp;gt;Git-2.44.0-64-bit.exe&amp;lt;/u&amp;gt; selecting &amp;quot;Git from the command line&amp;quot; from the following screen, then continue with all the default options afterwards:&lt;br /&gt;
&lt;br /&gt;
[[File:Git Install 1.png|border]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4)&#039;&#039;&#039; Open the Python installation file named &amp;lt;u&amp;gt;python-3.11.9-amd64.exe&amp;lt;/u&amp;gt; and on the first dialogue select &amp;quot;Add python.exe to PATH&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Python Install 1.png]]&lt;br /&gt;
&lt;br /&gt;
Keep all the default values on the following screen:&lt;br /&gt;
&lt;br /&gt;
[[File:Python Install 2.png]]&lt;br /&gt;
&lt;br /&gt;
Select &amp;quot;Install Pyhon 3.11 for all users&amp;quot; from the following screen: &#039;&#039;&#039;&amp;quot;Add Python to environment variables&amp;quot; has to be selected!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[File:Python Install 3.png]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;5)&#039;&#039;&#039; Once installation is complete you may need to logout of windows or restart your computer before the Powershell will recognize the new PATH entries for GIT and Python. To test if either program works, try the following commands after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol in Windows Powershell and you should see the following responses if all is well. If you do not see these responses or receive a &amp;quot;ObjectNotFound&amp;quot; type of error, then try the above installations again.&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;python -V&#039;&#039;&#039;&lt;br /&gt;
 Python 3.11.9&lt;br /&gt;
&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;git.exe -v&#039;&#039;&#039;&lt;br /&gt;
 git version 2.44.0.windows.1&lt;br /&gt;
&lt;br /&gt;
=== NPCAP Install (Optional) ===&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; If you are using CANBUS for your read/write functions, open and install the file named &amp;lt;u&amp;gt;npcap-1.79.exe&amp;lt;/u&amp;gt; using default options.&lt;br /&gt;
&lt;br /&gt;
=== GKFlasher Setup ===&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; Open your Powershell or Command prompt and change to the desired directory where you will be installing the GKFlasher files. A typical example directory might be in C:\GIT Repos\ so create yourself a directory in the C:\ drive named &amp;quot;GIT Repos&amp;quot; for this example. Use the following commands after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol:&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;mkdir &amp;quot;C:\GIT Repos&amp;quot;&#039;&#039;&#039;&lt;br /&gt;
 &lt;br /&gt;
     Directory: C:\&lt;br /&gt;
 &lt;br /&gt;
 Mode                 LastWriteTime         Length Name&lt;br /&gt;
 ----                 -------------         ------ ----&lt;br /&gt;
 d-----          4/6/2024   7:10 PM                GIT Repos&lt;br /&gt;
&#039;&#039;&#039;2)&#039;&#039;&#039; Change to the &amp;quot;GIT Repos&amp;quot; directory and run the GIT command to download the GKFlasher files to your desired directory using the following command after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol:&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;cd &amp;quot;C:\GIT Repos&amp;quot;&#039;&#039;&#039;&lt;br /&gt;
 &lt;br /&gt;
 PS C:\GIT Repos&amp;gt; &#039;&#039;&#039;git clone &amp;lt;nowiki&amp;gt;https://github.com/Dante383/GKFlasher&amp;lt;/nowiki&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
 Cloning into &#039;GKFlasher&#039;...&lt;br /&gt;
 remote: Enumerating objects: 1071, done.&lt;br /&gt;
 remote: Counting objects: 100% (117/117), done.&lt;br /&gt;
 remote: Compressing objects: 100% (69/69), done.&lt;br /&gt;
 remote: Total 1071 (delta 58), reused 96 (delta 48), pack-reused 954&lt;br /&gt;
 Receiving objects: 100% (1071/1071), 446.77 KiB | 7.45 MiB/s, done.&lt;br /&gt;
 Resolving deltas: 100% (672/672), done.&lt;br /&gt;
&#039;&#039;&#039;3)&#039;&#039;&#039; Change to the GKFlasher directory then install the required Python packages with the following commands after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol:&lt;br /&gt;
 PS C:\GIT Repos&amp;gt; &#039;&#039;&#039;cd GKFlasher&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 PS C:\GIT Repos\GKFlasher&amp;gt; &#039;&#039;&#039;python -m pip install -r requirements.txt&#039;&#039;&#039;&lt;br /&gt;
 Requirement already satisfied: alive_progress==3.1.5 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 1)) (3.1.5)&lt;br /&gt;
 Requirement already satisfied: crcmod==1.7 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 2)) (1.7)&lt;br /&gt;
 Requirement already satisfied: gkbus==0.1.8 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 3)) (0.1.8)&lt;br /&gt;
 Requirement already satisfied: pyftdi==0.55.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 4)) (0.55.0)&lt;br /&gt;
 Requirement already satisfied: pyqt5==5.15.9 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 5)) (5.15.9)&lt;br /&gt;
 Requirement already satisfied: PyYAML==6.0.1 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 6)) (6.0.1)&lt;br /&gt;
 Requirement already satisfied: about-time==4.2.1 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from alive_progress==3.1.5-&amp;gt;-r requirements.txt (line 1)) (4.2.1)&lt;br /&gt;
 Requirement already satisfied: grapheme==0.6.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from alive_progress==3.1.5-&amp;gt;-r requirements.txt (line 1)) (0.6.0)&lt;br /&gt;
 Requirement already satisfied: pyserial==3.5 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from gkbus==0.1.8-&amp;gt;-r requirements.txt (line 3)) (3.5)&lt;br /&gt;
 Requirement already satisfied: scapy==2.5.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from gkbus==0.1.8-&amp;gt;-r requirements.txt (line 3)) (2.5.0)&lt;br /&gt;
 Requirement already satisfied: pyusb!=1.2.0,&amp;gt;=1.0.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from pyftdi==0.55.0-&amp;gt;-r requirements.txt (line 4)) (1.2.1)&lt;br /&gt;
 Requirement already satisfied: PyQt5-sip&amp;lt;13,&amp;gt;=12.11 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from pyqt5==5.15.9-&amp;gt;-r requirements.txt (line 5)) (12.13.0)&lt;br /&gt;
 Requirement already satisfied: PyQt5-Qt5&amp;gt;=5.15.2 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from pyqt5==5.15.9-&amp;gt;-r requirements.txt (line 5)) (5.15.2)&lt;br /&gt;
&#039;&#039;&#039;4)&#039;&#039;&#039; If everything went well you should now be able to start the GKFlasher GUI with the USB cable plugged in. Try the following command and you should see the GKFlasher window appear:&lt;br /&gt;
 PS C:\GIT Repos\GKFlasher&amp;gt; &#039;&#039;&#039;python gui.py&#039;&#039;&#039;&lt;br /&gt;
[[File:GKFlasher First Time.png|701x701px]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;5) Optional:&#039;&#039;&#039; Create a desktop shortcut to open GKFlasher easily. First we&#039;ll need to know the location of your python3.11.exe executable. Execute the following command from your Powershell or command prompt and enter the command after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol. The following line you will use to copy/paste into your desktop shortcut. In this example it is located in my local user&#039;s directory within a subfolder. Yours will vary depending on your username.&lt;br /&gt;
 PS C:\GIT Repos\GKFlasher&amp;gt; &#039;&#039;&#039;(Get-Command python.exe).Path&#039;&#039;&#039;&lt;br /&gt;
 C:\Users\cfham\AppData\Local\Microsoft\WindowsApps\python.exe&lt;br /&gt;
Right click on your desktop and go to &amp;quot;New&amp;quot; and &amp;quot;Shortcut&amp;quot;, then paste the line you found from the last Powershell command and click next:&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 1.png]]&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 2.png|border]]&lt;br /&gt;
&lt;br /&gt;
Type in &amp;quot;GKFlasher&amp;quot; into the next window and press Finish:&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 3.png|border]]&lt;br /&gt;
&lt;br /&gt;
Now right click on that new shortcut and select properties. You will change a couple of settings in this new window so that it starts the GKFlasher app and change to the correct starting directory. First add &amp;quot; gui.py&amp;quot; (Contains a space) to the end of the target prompt and copy/paste the directory location you chose for your GIT Repos containing GKFlasher and press apply. The following is using my example directory. Yours may be unique.&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 4.png|border]]&lt;br /&gt;
&lt;br /&gt;
If you would like to add an icon to your shortcut, you can download the OpenGK/GKFlasher logo from [https://opengk.org/files/Users/chase206/Siemens_T_Logo.ico Siemens_T_Logo.ico] and add it to your GKFLasher shortcut using the &amp;quot;Change Icon&amp;quot; button.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
	<entry>
		<id>https://opengk.org:443/index.php?title=GKFlasher_Instructions&amp;diff=460</id>
		<title>GKFlasher Instructions</title>
		<link rel="alternate" type="text/html" href="https://opengk.org:443/index.php?title=GKFlasher_Instructions&amp;diff=460"/>
		<updated>2024-12-08T21:19:29Z</updated>

		<summary type="html">&lt;p&gt;Dmg210: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
GKFlasher is an open source Python project supported by OpenGK, written by dante383 and dmg210. This project is a multi OBD2 tool for the Siemens ECUs found on the Hyundai and Kia vehicles. It can read &amp;amp; write tune data, correct EEPROM checksums and clear adaptive values from your ECU. The purpose of this article is to instruct you how to download, install and configure all the prerequisites for GKFlasher. If you are a GitHub user, please go star the following repository:&lt;br /&gt;
&lt;br /&gt;
https://github.com/Dante383/GKFlasher&lt;br /&gt;
&lt;br /&gt;
== Windows 10 &amp;amp; 11 Installation ==&lt;br /&gt;
=== Prerequisites ===&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; First you will need a FTDI USB-OBD2 interface cable. This is often the same cable used on German vehicles. The chipset on the board must be a real FTDI chip and cannot be one of the CH340C chips. Through extensive testing we found that the following cable is the least expensive and most reliable cable for GKFlasher:&lt;br /&gt;
&lt;br /&gt;
[https://www.aliexpress.us/item/2251832612703671.html &amp;lt;s&amp;gt;Galletto 1260 ECU Chip Tuning Tool EOBD Programmer FTDI&amp;lt;/s&amp;gt;] There is a bug with these adapters preventing the hardware flow control from being disabled. These adapters no longer work with GKFlasher and fail on fast-init stage.   &lt;br /&gt;
&lt;br /&gt;
Pictured here shows the good FTDI chipset and the bad CH340C chipset. Avoid the CH340C chipsets completely.&lt;br /&gt;
&lt;br /&gt;
[[File:FTDI Example.png|269x269px]]:[[File:CH340C Example.png]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;*&amp;lt;/nowiki&amp;gt;from GKFlasher v1.0.5 we have added support for the CH340 chipset. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2)&#039;&#039;&#039; Download the following files:&lt;br /&gt;
&lt;br /&gt;
[https://github.com/git-for-windows/git/releases/download/v2.44.0.windows.1/Git-2.44.0-64-bit.exe Git-2.44.0-64-bit.exe]&lt;br /&gt;
&lt;br /&gt;
[https://www.python.org/ftp/python/3.11.9/python-3.11.9-amd64.exe python-3.11.9-amd64.exe]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Optional download for npcap if you are using a CAN BUS interface for a specific purpose:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[https://npcap.com/dist/npcap-1.79.exe npcap-1.79.exe]&lt;br /&gt;
&lt;br /&gt;
=== Install GIT &amp;amp; Python ===&lt;br /&gt;
&#039;&#039;&#039;3)&#039;&#039;&#039; Open the Git install file named &amp;lt;u&amp;gt;Git-2.44.0-64-bit.exe&amp;lt;/u&amp;gt; selecting &amp;quot;Git from the command line&amp;quot; from the following screen, then continue with all the default options afterwards:&lt;br /&gt;
&lt;br /&gt;
[[File:Git Install 1.png|border]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4)&#039;&#039;&#039; Open the Python installation file named &amp;lt;u&amp;gt;python-3.11.9-amd64.exe&amp;lt;/u&amp;gt; and on the first dialogue select &amp;quot;Add python.exe to PATH&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Python Install 1.png]]&lt;br /&gt;
&lt;br /&gt;
Keep all the default values on the following screen:&lt;br /&gt;
&lt;br /&gt;
[[File:Python Install 2.png]]&lt;br /&gt;
&lt;br /&gt;
Select &amp;quot;Install Pyhon 3.11 for all users&amp;quot; from the following screen: &#039;&#039;&#039;&amp;quot;Add Python to environment variables&amp;quot; has to be selected!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[File:Python Install 3.png]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;5)&#039;&#039;&#039; Once installation is complete you may need to logout of windows or restart your computer before the Powershell will recognize the new PATH entries for GIT and Python. To test if either program works, try the following commands after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol in Windows Powershell and you should see the following responses if all is well. If you do not see these responses or receive a &amp;quot;ObjectNotFound&amp;quot; type of error, then try the above installations again.&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;python -V&#039;&#039;&#039;&lt;br /&gt;
 Python 3.11.9&lt;br /&gt;
&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;git.exe -v&#039;&#039;&#039;&lt;br /&gt;
 git version 2.44.0.windows.1&lt;br /&gt;
&lt;br /&gt;
=== NPCAP Install (Optional) ===&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; If you are using CANBUS for your read/write functions, open and install the file named &amp;lt;u&amp;gt;npcap-1.79.exe&amp;lt;/u&amp;gt; using default options.&lt;br /&gt;
&lt;br /&gt;
=== GKFlasher Setup ===&lt;br /&gt;
&#039;&#039;&#039;1)&#039;&#039;&#039; Open your Powershell or Command prompt and change to the desired directory where you will be installing the GKFlasher files. A typical example directory might be in C:\GIT Repos\ so create yourself a directory in the C:\ drive named &amp;quot;GIT Repos&amp;quot; for this example. Use the following commands after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol:&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;mkdir &amp;quot;C:\GIT Repos&amp;quot;&#039;&#039;&#039;&lt;br /&gt;
 &lt;br /&gt;
     Directory: C:\&lt;br /&gt;
 &lt;br /&gt;
 Mode                 LastWriteTime         Length Name&lt;br /&gt;
 ----                 -------------         ------ ----&lt;br /&gt;
 d-----          4/6/2024   7:10 PM                GIT Repos&lt;br /&gt;
&#039;&#039;&#039;2)&#039;&#039;&#039; Change to the &amp;quot;GIT Repos&amp;quot; directory and run the GIT command to download the GKFlasher files to your desired directory using the following command after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol:&lt;br /&gt;
 PS C:\Users\cfham&amp;gt; &#039;&#039;&#039;cd &amp;quot;C:\GIT Repos&amp;quot;&#039;&#039;&#039;&lt;br /&gt;
 &lt;br /&gt;
 PS C:\GIT Repos&amp;gt; &#039;&#039;&#039;git clone &amp;lt;nowiki&amp;gt;https://github.com/Dante383/GKFlasher&amp;lt;/nowiki&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
 Cloning into &#039;GKFlasher&#039;...&lt;br /&gt;
 remote: Enumerating objects: 1071, done.&lt;br /&gt;
 remote: Counting objects: 100% (117/117), done.&lt;br /&gt;
 remote: Compressing objects: 100% (69/69), done.&lt;br /&gt;
 remote: Total 1071 (delta 58), reused 96 (delta 48), pack-reused 954&lt;br /&gt;
 Receiving objects: 100% (1071/1071), 446.77 KiB | 7.45 MiB/s, done.&lt;br /&gt;
 Resolving deltas: 100% (672/672), done.&lt;br /&gt;
&#039;&#039;&#039;3)&#039;&#039;&#039; Change to the GKFlasher directory then install the required Python packages with the following commands after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol:&lt;br /&gt;
 PS C:\GIT Repos&amp;gt; &#039;&#039;&#039;cd GKFlasher&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 PS C:\GIT Repos\GKFlasher&amp;gt; &#039;&#039;&#039;python -m pip install -r requirements.txt&#039;&#039;&#039;&lt;br /&gt;
 Requirement already satisfied: alive_progress==3.1.5 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 1)) (3.1.5)&lt;br /&gt;
 Requirement already satisfied: crcmod==1.7 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 2)) (1.7)&lt;br /&gt;
 Requirement already satisfied: gkbus==0.1.8 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 3)) (0.1.8)&lt;br /&gt;
 Requirement already satisfied: pyftdi==0.55.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 4)) (0.55.0)&lt;br /&gt;
 Requirement already satisfied: pyqt5==5.15.9 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 5)) (5.15.9)&lt;br /&gt;
 Requirement already satisfied: PyYAML==6.0.1 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from -r requirements.txt (line 6)) (6.0.1)&lt;br /&gt;
 Requirement already satisfied: about-time==4.2.1 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from alive_progress==3.1.5-&amp;gt;-r requirements.txt (line 1)) (4.2.1)&lt;br /&gt;
 Requirement already satisfied: grapheme==0.6.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from alive_progress==3.1.5-&amp;gt;-r requirements.txt (line 1)) (0.6.0)&lt;br /&gt;
 Requirement already satisfied: pyserial==3.5 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from gkbus==0.1.8-&amp;gt;-r requirements.txt (line 3)) (3.5)&lt;br /&gt;
 Requirement already satisfied: scapy==2.5.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from gkbus==0.1.8-&amp;gt;-r requirements.txt (line 3)) (2.5.0)&lt;br /&gt;
 Requirement already satisfied: pyusb!=1.2.0,&amp;gt;=1.0.0 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from pyftdi==0.55.0-&amp;gt;-r requirements.txt (line 4)) (1.2.1)&lt;br /&gt;
 Requirement already satisfied: PyQt5-sip&amp;lt;13,&amp;gt;=12.11 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from pyqt5==5.15.9-&amp;gt;-r requirements.txt (line 5)) (12.13.0)&lt;br /&gt;
 Requirement already satisfied: PyQt5-Qt5&amp;gt;=5.15.2 in c:\users\cfham\appdata\local\packages\pythonsoftwarefoundation.python.3.11_qbz5n2kfra8p0\localcache\local-packages\python311\site-packages (from pyqt5==5.15.9-&amp;gt;-r requirements.txt (line 5)) (5.15.2)&lt;br /&gt;
&#039;&#039;&#039;4)&#039;&#039;&#039; If everything went well you should now be able to start the GKFlasher GUI with the USB cable plugged in. Try the following command and you should see the GKFlasher window appear:&lt;br /&gt;
 PS C:\GIT Repos\GKFlasher&amp;gt; &#039;&#039;&#039;python gui.py&#039;&#039;&#039;&lt;br /&gt;
[[File:GKFlasher First Time.png|701x701px]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;5) Optional:&#039;&#039;&#039; Create a desktop shortcut to open GKFlasher easily. First we&#039;ll need to know the location of your python3.11.exe executable. Execute the following command from your Powershell or command prompt and enter the command after the &#039;&#039;&#039;&amp;gt;&#039;&#039;&#039; symbol. The following line you will use to copy/paste into your desktop shortcut. In this example it is located in my local user&#039;s directory within a subfolder. Yours will vary depending on your username.&lt;br /&gt;
 PS C:\GIT Repos\GKFlasher&amp;gt; &#039;&#039;&#039;(Get-Command python.exe).Path&#039;&#039;&#039;&lt;br /&gt;
 C:\Users\cfham\AppData\Local\Microsoft\WindowsApps\python.exe&lt;br /&gt;
Right click on your desktop and go to &amp;quot;New&amp;quot; and &amp;quot;Shortcut&amp;quot;, then paste the line you found from the last Powershell command and click next:&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 1.png]]&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 2.png|border]]&lt;br /&gt;
&lt;br /&gt;
Type in &amp;quot;GKFlasher&amp;quot; into the next window and press Finish:&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 3.png|border]]&lt;br /&gt;
&lt;br /&gt;
Now right click on that new shortcut and select properties. You will change a couple of settings in this new window so that it starts the GKFlasher app and change to the correct starting directory. First add &amp;quot; gui.py&amp;quot; (Contains a space) to the end of the target prompt and copy/paste the directory location you chose for your GIT Repos containing GKFlasher and press apply. The following is using my example directory. Yours may be unique.&lt;br /&gt;
&lt;br /&gt;
[[File:GKFlasher Desktop Shortcut 4.png|border]]&lt;br /&gt;
&lt;br /&gt;
If you would like to add an icon to your shortcut, you can download the OpenGK/GKFlasher logo from [https://opengk.org/files/Users/chase206/Siemens_T_Logo.ico Siemens_T_Logo.ico] and add it to your GKFLasher shortcut using the &amp;quot;Change Icon&amp;quot; button.&lt;/div&gt;</summary>
		<author><name>Dmg210</name></author>
	</entry>
</feed>