
Published: July 29, 2026 · Last updated: July 29, 2026
Every immobiliser job on an Immo 2 Opel or Vauxhall starts with the same four digits. Add a key, replace an ECU, fit a cluster from another car, recover from all keys lost: none of it moves without the code.
If the Car Pass is gone, the code is still in the car. It is stored in four separate modules, and you only need one of them to give it up.
I did this on a 2006 Corsa C. The same immobox family sits in the other cars listed below, so the method should carry across, but one car is what I have actually verified.
I earn from qualifying purchases and sometimes get tools for free (full disclosure). It never affects my scoring.
Quick answer
✅ The code is in four places. Instrument cluster, engine ECU, BCM and immobox all hold the same four digits. The cluster and the ECU can be read over OBD with tools you probably already own. The BCM and the immobox need the module out and read on the bench.
Work through them in that order. Most people never get past the first one.
What this code actually is
The four digits printed on the Car Pass and the security code stored in the modules are the same number. There is no separate “module code”. If you have the Car Pass, you already have what this article is about.
It is always four digits and always numbers, never letters. Anything longer or with letters is a different code, usually the radio code.
A dealer can issue a replacement Car Pass if you can prove the car is yours. It costs money and takes time, but it is the legitimate route and worth a phone call before you start taking modules apart.
Which cars this covers
| Model | Years | Status |
|---|---|---|
| Corsa C | 2000 to 2006 | Verified on my own car |
| Astra G | 1998 to 2009 | Same immobox family |
| Zafira A | 1999 to 2005 | Same immobox family |
| Meriva A | 2003 to 2010 | Same immobox family |
| Tigra B | 2004 to 2009 | Same immobox family |
| Combo C | 2001 to 2011 | Same immobox family |
| Agila A | 2000 to 2007 | Same immobox family |
| Vectra B | 1999 to 2002 | Same immobox family, later cars only |
| Omega B | 1999 to 2003 | Same immobox family, later cars only |
| Sintra | 1999 to 2001 | Same immobox family |
Vectra B and Omega B straddle both generations. Early cars are Immo 1, later cars are Immo 2, so check the car rather than the badge.
The Fiat Sedici and Suzuki SX4 are reported to use the same Siemens immobox, but I have not seen one and cannot confirm it.
Astra F, Corsa B and early Vectra B are Immo 1. Different system, this does not apply.
Before you take anything apart
Confirm the car actually has an immobiliser. Open the engine ECU measuring blocks and look for the immobiliser function flag. If it reads as programmed, you are in the right place.
All four modules store the same code, so you only need one of them to talk to you. Which one is easiest comes down to what tools you already own.
Do not start guessing. Every wrong attempt starts a lockout timer, and they get long enough to ruin a weekend. There is a section on that at the end.
The four locations, in the order worth trying
| Module | Where the code sits | Access | Tool |
|---|---|---|---|
| Instrument cluster | Internal memory | OBD, car stays together | OP-COM or Autel |
| Engine ECU | EEPROM | OBD | Autel, KT200 |
| BCM | EEPROM | Bench, chip desoldered | EEPROM programmer |
| Immobox | MCU | Bench, module out, wired to pinout | Orange 5 |
The order is about effort, not reliability. All four hold the same number.
1. Instrument cluster, over OBD

This is the one to try first and the reason most people never need the rest of this article.
Go to instrument cluster module.
Autel path: special functions > get security code
Opcom path: eeprom menu > read security code
Both OP-COM and an Autel tablet read the code straight out of the cluster over the OBD socket. The cluster stays in the dash. Nothing gets opened, nothing gets unplugged.
There is a long-running forum argument about whether the Corsa C cluster stores this in an EEPROM or in the NEC chip. It does not matter on this path. I have never had my cluster open and both tools returned the code.
💡 Try another software build first. Forums insisted I needed OP-COM firmware 1.39 for immobiliser work. I bought a flashable adapter and never flashed it. Three software builds came with it, one handled key programming and another handled cluster replacement. Switching builds is free and reversible. Flashing firmware is neither.
2. Engine ECU, over OBD

Also an OBD job if your tool can read the ECU EEPROM. I used a KT200. I was not sure if the code is in eeprom or flash, so I red both.
You only need the EEPROM.
Drop the resulting dump into a calculator to pull the four digits out.
🧰 Use this calculator to extract pin code from eeprom dump
3. BCM, on the bench

This is where it gets physical. None of my tools reached the BCM over OBD, so the module comes out, the EEPROM chip gets desoldered, read externally, then soldered back.

It is a real soldering job on a board that runs the car’s body electrics, but it is straightforward work on a package you can see and reach. Of the two bench methods, this is the one I would do first.
🧰 Use this calculator to extract pin code from eeprom dump
4. Immobox, on the bench

Hardest of the four by a wide margin, and the one I would leave until everything else has failed. The module comes out and the MCU gets read directly, wired up according to the pinout.
First remove the cover and desolder antena joints to get to other side where the chip sits.

I saw 4-digit number on both immobox I red, but this was not password even though these numbers differed in different immoboxes.

Two chip variants live inside the same box. A Motorola HC908AB16A in a QFP64 package, which is security locked, or a TI TMS370C702 in a square PLCC28 package. Which one you have changes how you read it. It changes nothing about the other three methods.
⚠️ These tools didn’t work. A Carprog clone and an iProg+ v87 both failed on this MCU. An original Carprog is reported to handle it, but I do not have one to confirm. An Orange 5 clone read it after few tries.
How to read QFP64 chip with Orange 5 clone
First lift the PINS 2, 26 and 60 from circuit board.

Check oscillator number – you will need to input it in Orange before reading. Mine had 8000.

For PIN 60 connecting to VCC you need to use 1 kΩ resistor.

Connect wires from Orange 5 according to this schema.

Orange will ask for security byte code, use this one:
SS= F3 B1 F3 AB F3 A5 F3 9F
With everything connected read the chip data.

Worth knowing before you spend money: Autel documents a bench read on this MCU for Astra, Combo, Corsa, Meriva and Vectra of this era, with its own pinout. I did not test it, because my immobox was a replacement and the board did not match the illustration on screen. If you own an Autel and your box is original, try that before buying a dedicated programmer.
🧰 Use this calculator to extract pin code from eeprom dump
When the car has already been worked on
Old cars have history, and on an immobiliser system somebody else’s repair becomes your problem. Car I worked on had matching password in BCM, ECU and IPC but the immobox was from different car and had own transponder glued to top of it.
That’s why I keep failing trying to do resets, immo programming or key programming after I erased the keys. Password was not same in all modules.

🔧 What actually happened on my Corsa. A previous owner had replaced the immobox, and whoever fitted it had glued a transponder to the top of the module. The original key was not what authorised the start. That glued transponder was. So when I reset the modules I erased all the keys, and the car that had been starting fine that morning stopped starting at all.
The lesson is not “don’t reset”. The lesson is that before you reset anything, look at the modules physically and confirm what is actually authorising the start.
Once you have the code
The code by itself unlocks the programming functions. What you do with them is a separate job, and I have written those up as their own procedures.
⚠️ Reset with original pin from donor car. Resetting the immobiliser wipes every programmed key and leaves the car dead until you program one back, and a reset immobiliser will then accept any code you give it. So if you are taking an immobox, engine ECU or cluster out of a donor car, reset it with donor’s carpass not with yours.
If the system is already locked out
Wrong code attempts start a wait timer, and it escalates hard.
Security wait times. Ten seconds, then ten minutes, twenty, forty, one hour twenty, two hours forty, five hours twenty, ten hours forty, and finally 21 hours and 20 minutes.
⚠️ The timer is not a countdown. Live data shows the length of the lockout, not the time remaining. Mine sat at 21 hours 20 minutes and stayed on that same value the entire time, never moving. It only switched to inactive once the full period had actually elapsed. I spent a good while assuming the reading was frozen or that I was looking at the wrong field.
The timer only advances with the ignition on. Leave the ignition on and put a charger on the battery, otherwise the wait never ends and you flatten the battery trying. On a 21 hour lockout that is not optional.
Tools you’ll need
For the two OBD methods, an OP-COM or a scan tool that supports Opel immobiliser functions. For the ECU dump, a flasher such as the KT200. For the BCM, an EEPROM programmer and a soldering iron you trust. For the immobox, an Orange 5.
Most popular OBD2 guides
Hi, I am Juraj Lukacko. I got frustrated by unhelpful and scammy mechanics, so I decided to learn everything about car diagnostics myself. I test dozens of new car diagnostic tools every month along with learning new strategies to fix and customize cars.
