Like many people, I had a Canon printer (in my case, a PIXMA MG2920) that stopped printing because of the dreaded ink absorber issue: after several years of good service, the alarm for "ink absorber is almost full" caused me to press "stop" before every print, until the alternate flashing of the alarm and power lights would signal "ink absorber is full" and the printer would simply stop printing.
Like many people, I found out about the "Canon Service Tool" from several, repetitive posts and videos all around the Internet, promising to fix my printer quick and easy.
And like many people, after trying every single version I could find of the "Canon Service Tool" and discovering that none of them fixed the ink absorber error, I found out, puzzled, that my printer wouldn't even enter the service mode anymore.
And thanks to
Rainbow's post on 9/7/2019 in this very thread, I was able to finally get my MG2920 working again and would like to share some info and tips as a way of thanks.
I believe that the info here applies to the MG2900 series, since as far as I understand, the different MG29X0 models are intended for different regions of the world (10 for Latin America, 20 for North America, 50 for Europe or Asia, something like that, I think).
Rainbow is correct that the "Canon Service Tool" won't reset the ink absorber, no matter the version. Don't ever bother. The only version 4905 I found was infected with viruses; v4906, v5103 and v5306 didn't work; v3400 or v3600 caused the printer not to enter service mode anymore.
But you'll find several sites listing one or more versions of the "Canon Service Tool", also stating that v4905 (or other version) works with the PIXMA MG2920 (or any of the MG2900 series). There are even sites selling the tool for about $10, and some more honest ones, like
this forum, lists several Canon printers (including MG2910) that can't have the ink absorber reset.
As stated in posts in this thread and detailed by Rainbow, the only solution is to reflash the printer's EEPROM. Which is, as already stated here, also the only solution to unblock the printer's service mode. There's a
YouTube video where a person reproduces the blocked service mode issue by using an old service tool, then desoldering+reflashing+resoldering the printer's EEPROM, and showing that it works again.
You might be lucky and find a working, slightly used logic board of your printer on eBay (like
this one). If so, just replace it and you're done.
In theory it should be possible to reflash the EEPROM using a programmer and a clip, but from what I understand that might simply not work (because the programmer doesn't have enough power to feed the EEPROM and the logic board it's attached to) or, even worse, cause the EEPROM to be erased (because of the EEPROM being in a circuit that you don't know how it behaves). I didn't want to risk the only EEPROM I had (plus I didn't have a backup of the contents to restore it) so I took the hard, safer path.
Desoldering and resoldering the EEPROM is up to you. If you don't have experience with a soldering iron, I don't recommend trying it, as it's pretty easy to damage the chip and/or the board. Try finding someone who can do it for you. It's the best advice I can give you.
In the MG2920 (and MG2910 it seems), the EEPROM part number is 25Q064A13E40 (first two lines of the chip). The number 3 (before letter E) indicates that it's a 3V EEPROM (if it's a 1, it's a 1.8V EEPROM). This is important so you get the right programmer for the EEPROM. For more technical details, search for the part number on
Micron's website (omit the last two digits though, eg search for 25Q064A13E).
If you decide to buy a cheap EEPROM/flash programmer (like
https://www.amazon.com/AiTrip-EEPROM-Programmer-CH341A-Adapter/dp/B07VNVVXW6 or any of its clones, with a black board) make sure it doesn't have a design flaw where data lines are using 5V instead of 3V; I didn't want to risk toasting my EEPROM and didn't buy one of them. Instead, I had a Raspberry Pi handy and connected the EEPROM with a few wires, according to
https://www.flashrom.org/RaspberryPi which resulted in the following connections:
| EEPROM pin | Raspberry Pi pin |
|---|
| 1 | 24 |
| 2 | 21 |
| 3 | 17 |
| 4 | 25 |
| 5 | 19 |
| 6 | 23 |
| 7 | 17 |
| 8 | 17 |
To program the EEPROM the easiest options are
flashrom (on Linux) or
AsProgrammer (on Windows).
AsProgrammer can be found at
https://github.com/nofeletru/UsbAsp-flash/releases and contains drivers and the tool itself; just install the right driver for your programmer and run the tool.
flashrom can be installed with a simple
sudo apt install flashrom on Linux.
Once the EEPROM is ready, read it and save the contents somewhere safe (it's an 8MB file). Now apply the changes detailed by Rainbow in the post (replace the byte
0x44 at offsets
0x2a and
0x102a with a
00; replace the 32 bytes at offsets
0xd0 and
0x10d0 with
63 a5 40 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00) and write the EEPROM back.
This is what is looks like in my Raspberry Pi:
$ modprobe spi_bcm2835
$ modprobe spidev
$ sudo flashrom --programmer linux_spi:dev=/dev/spidev0.0,spispeed=1000 -r mg2920.bin
flashrom on Linux 5.10.11-v7+ (armv7l)
flashrom is free software, get the source code at https://flashrom.org
Using clock_gettime for delay loops (clk_id: 1, resolution: 1ns).
Found Micron/Numonyx/ST flash chip "N25Q064..3E" (8192 kB, SPI) on linux_spi.
Reading flash... done.
$ cp mg2920.bin mg2920.bin.backup
$ hexedit mg2920.bin
$ xxd mg2920.bin.backup > b1.hex
$ xxd mg2920.bin > b2.hex
$ diff b1.hex b2.hex
3c3
< 00000020: 2f2f 0000 0000 0000 0053 4400 3007 0000 //.......SD.0...
---
> 00000020: 2f2f 0000 0000 0000 0053 0000 3007 0000 //.......S..0...
14,15c14,15
< 000000d0: 44ee 4000 0000 0000 0000 0000 cae7 0500 D.@.............
< 000000e0: bff3 0200 0000 0000 89db 0800 0000 0000 ................
---
> 000000d0: 63a5 4000 0000 0000 0000 0000 0100 0000 c.@.............
> 000000e0: 0000 0000 0000 0000 0100 0000 0000 0000 ................
259c259
< 00001020: 2f2f 0000 0000 0000 0053 4400 3007 0000 //.......SD.0...
---
> 00001020: 2f2f 0000 0000 0000 0053 0000 3007 0000 //.......S..0...
270,271c270,271
< 000010d0: 44ee 4000 0000 0000 0000 0000 cae7 0500 D.@.............
< 000010e0: bff3 0200 0000 0000 89db 0800 0000 0000 ................
---
> 000010d0: 63a5 4000 0000 0000 0000 0000 0100 0000 c.@.............
> 000010e0: 0000 0000 0000 0000 0100 0000 0000 0000 ................
$ rm b1.hex b2.hex
$ sudo flashrom --programmer linux_spi:dev=/dev/spidev0.0,spispeed=1000 -w mg2920.bin
flashrom on Linux 5.10.11-v7+ (armv7l)
flashrom is free software, get the source code at https://flashrom.org
Using clock_gettime for delay loops (clk_id: 1, resolution: 1ns).
Found Micron/Numonyx/ST flash chip "N25Q064..3E" (8192 kB, SPI) on linux_spi.
Reading old flash chip contents... done.
Erasing and writing flash chip... Erase/write done.
Verifying flash... VERIFIED.
Once you put the EEPROM back, your MG2920 should be working fine. You can use the service tool to print the contents of the EEPROM and double check that the ink absorber count is now 0.
Below is the dump of the EEPROM with the ink absorber field reset, so it's ready to be flashed (like the service tool, there are several websites selling them for $5-$10). However, I only recommend doing it as a last resort (eg your EEPROM was erased) since it will change a lot of parameters in your print (which I have no idea what they mean). One possibility (although untested) is, if you have printed the content of the EEPROM using the service tool earlier, to update the dump I provided with the values you printed: just remember to type them again at offset
0x1000, and that each 16-bit pair XXYY in the dump should be typed as YY XX in your hex editor.
I hope this long post helps users in the same situation I was. Happy fixing!