Once the password is encrypted it cannot be decrypted. If the user forgets their password, they have to enter in a new password on your site, or you generate a random password and send that to them and then they visit your site log in with the new password and update the password to whatever they want.
To do this, take a look at the Solution Recipes for SecurityAssist: securityassist/, in particular take a look at the "Updating Send Password", but you may want to view some of the other recepies above it as well.