md5 is a hash function, and hash functions are designed to have two properties:
1) they are hiding. You (theoretically) can't reverse the function by any method other than brute-force.
2) they are *binding. You (theoretically) can't find any other input that hashes to the same output by any method other than brute-force.
Any tool that "decrypts" md5 hashes most likely does so by generating what is called a rainbow table -- a giant list of many possible inputs, and the hashes they generate. If you look at the spreadsheet and find a hash from your rainbow table, voila, you know what it came from. To make it harder to use rainbow tables, any security-conscious site will "salt" the passwords before hashing them, by adding a random string prefix. The point is for the random "salt" to be different for each password you are hashing, so a standard (unsalted) rainbow table won't work, and further, the same rainbow table won't work for every password.
(md5 itself has been shown to be vulnerable to collision attacks, which is why I said "theoretically")