When the user signs up, store a Timestamp for creation date, then take their email address and use it as a prefix and suffix to salt the password, for instance:
If the users password is shanelja, then the routine would be as such:
TIMESTAMPshaneljaEMAIL
or in my case:
147182994718shaneljashanea93@hotmail.co.uk
This produces a ridiculously hard password to brute force.
While this may be easy to compute if you know the rule, the general rule of thumb is that if your server has been attacked in such a way that the attacker has a copy of your database, they will most likely know the rule in any case, so it makes sense to have a good one.
Outside of this, no one should be using MD5 in this day and age, I would even recommend against Sha256 and other variants in that family, though I have a lot of respect for Blowfish, etc.